Whitelist a bunch of url protocols.
[lhc/web/wiklou.git] / RELEASE-NOTES-1.22
1 Security reminder: MediaWiki does not require PHP's register_globals. If you
2 have it on, turn it '''off''' if you can.
3
4 == MediaWiki 1.22 ==
5
6 THIS IS NOT A RELEASE YET
7
8 MediaWiki 1.22 is an alpha-quality branch and is not recommended for use in
9 production.
10
11 === Configuration changes in 1.22 ===
12 * $wgRedirectScript was removed. It was unused.
13 * Removed $wgLocalMessageCacheSerialized, it is now always true.
14 * When $wgUseVFormUserLogin is true, the redesign of Special:UserLogin is
15 activated; when $wgUseVFormCreateAccount is true, the redesign of
16 Special:UserLogin/signup is activated.
17 * $wgVectorUseIconWatch is now enabled by default.
18 * $wgCascadingRestrictionLevels was added.
19 * ftps, ssh, sftp, xmpp, sip, sips, tel, sms, bitcoin, magnet, urn, and geo
20 have been whitelisted inside of $wgUrlProtocols.
21
22 === New features in 1.22 ===
23 * (bug 44525) mediawiki.jqueryMsg can now parse (whitelisted) HTML elements and attributes.
24 * (bug 33454) Language::sprintfDate now has a timezone parameter, and supports
25 the "eIOPTZ" formatting characters.
26 * EditWarning: A warning is shown when an editor leaves the edit form without
27 saving (enabled by default, users can opt-out via the 'useeditwarning'
28 preference). This feature was moved from the Vector extension, and is now part
29 of core for all skins. Take care when upgrading that you don't use an older
30 version of the Vector extension as this feature may conflict.
31 * New 'mediawiki.ui' CSS module providing mw-ui-* styles for buttons and a
32 compact vertical form layout.
33 * New versions of login (Special:UserLogin) and create account
34 (Special:UserLogin/signup) forms. They are opt-in for now, controlled by
35 the $wgUseVFormUserLogin and $wgUseVFormCreateAccount settings or a 'useNew'
36 URL parameter trigger.
37 * (bug 23343) Implemented ability to apply IP blocks to the contents of X-Forwarded-For headers
38 by adding a new configuration variable $wgApplyIpBlocksToXff (disabled by default).
39 * The new hook 'APIGetPossibleErrors' to modify the list of possible errors was
40 added.
41 * (bug 25592) LogEventsList::showLogExtract() will now ignore various
42 Pager-related WebRequest parameters by default, as this is overwhelmingly
43 likely to be what was intended by users of the method. If any caller wishes
44 to use these parameters, the new param 'useRequestParams' may be set to true.
45 * mw.util.addPortletLink: Tooltip is no longer required to be plain (without
46 an accesskey in it already). As such it now rountrips. Creating a link with a
47 message as tooltip, grabbing the title attribute and using it to create
48 another portlet will work as expected.
49 * (bug 6747) {{ROOTPAGENAME}} introduced, contains the name of the topmost
50 page without namespace.
51 * BREAKING CHANGE: (bug 41729) Display editsection links next to headings. Also
52 change their class name from .editsection to .mw-editsection and place them at
53 the end of the heading element instead of the beginning. Client-side code and
54 screen-scrapers will have to be adjusted to handle both cases (old HTML will
55 still be visible on cached page renders until they are purged); extensions
56 using the DoEditSectionLink or EditSectionLink hooks might need adjustments as
57 well.
58 * (bug 45535) introduced the new 'LanguageLinks' hook for manipulating the
59 language links associated with a page before display.
60 * Chosen (http://harvesthq.github.io/chosen/) was added as module 'jquery.chosen'
61 * HTMLForm will turn multiselect checkboxes into a Chosen interface when setting cssclass 'mw-chosen'
62 * rebuildLocalisationCache learned --lang option. Let you rebuild l10n caches
63 of the specified languages instead of all of them.
64 * New GetNewMessagesAlert hook allowing extensions to disable or modify the new
65 messages alert
66 * New wgUserNewMsgRevisionId JS global for logged in users. This will be null
67 if the user has no new talk page messages. Otherwise it will be set to the
68 revision ID of the oldest new talk page message. This will allow gadgets and
69 extensions to create their own new message alerts on the client side.
70 * mediawiki.log: Added log.warn wrapper (uses console.warn and console.trace).
71 * mediawiki.log: Implemented log.deprecate. This method defines a property and
72 uses ES5 getter/setter to emit a warning when they are used.
73 * $wgCascadingRestrictionLevels was added, allowing one to specify restriction levels
74 which can be cascading (previously 'sysop' was hard-coded as the only one).
75
76 === Bug fixes in 1.22 ===
77 * Disable Special:PasswordReset when $wgEnableEmail. Previously one could still
78 navigate to the page by entering the URL directly.
79 * (bug 47138) Fixed a fatal error when a blocked user tries to automatically
80 create an account on login due external authentication in some circumstances.
81 * (bug 23393) HTML <hN> headings containing line breaks are now handled
82 correctly.
83 * (bug 45803) Whitespace within == Headline == syntax and within <hN> headings
84 is now non-significant and not preserved in the HTML output.
85 * (bug 47218) Special:BlockList now handles correctly user names with spaces
86 when passed as subpage.
87 * Pager's properly validate which fields are allowed to be sorted on.
88 * mw.util.tooltipAccessKeyRegexp: The regex now matches "option-" as well.
89 Support for Mac "option" was added in 1.16, but the regex was never updated.
90 * (bug 46768) Usernames of blocking users now display correctly, even if numeric.
91 * (bug 39590) {{PAGESIZE}} for the current page and self-transclusions now
92 show the most up to date result always instead of being a revision behind.
93 * A bias in wfRandomString() toward digits 1-7 has been corrected. Generated
94 strings will now start with digits 0 and 8-f as often as they should.
95 * (bug 45371) Removed Parser_LinkHooks and CoreLinkFunctions classes.
96
97 === API changes in 1.22 ===
98 * (bug 46626) xmldoublequote parameter was removed. Because of a bug, the
99 parameter has had no effect since MediaWiki 1.16, and so its removal is
100 unlikely to impact existing clients.
101 * (bug 25325) Added support for wlshow filtering (bots/anon/minor/patrolled)
102 to action=feedwatchlist.
103 * WDDX formatted output will actually be formatted (and normal output will no
104 longer be), and will no longer choke on booleans.
105 * action=opensearch no longer silently ignores the format parameter.
106 * action=opensearch now supports format=jsonfm.
107 * list=usercontribs&ucprop=ids will now include the parent revision id.
108 * BREAKING CHANGE: action=parse no longer returns all langlinks for the page
109 with prop=langlinks by default. The new effectivelanglinks parameter will
110 request that the LanguageLinks hook be called to determine the effective
111 language links.
112 * BREAKING CHANGE: list=allpages, list=langbacklinks, and prop=langlinks do not
113 apply the new LanguageLinks hook, and thus only consider language links
114 stored in the database.
115 * (bug 47219) Allow specifying change type of Wikipedia feed items
116 * prop=imageinfo now allows setting iiurlheight without setting iiurlwidth
117 * prop=info now adds the content model of the title.
118 * New upload log entries will now contain information on the relavent
119 image (sha1 and timestamp).
120
121 === Languages updated in 1.22===
122
123 MediaWiki supports over 350 languages. Many localisations are updated
124 regularly. Below only new and removed languages are listed, as well as
125 changes to languages because of Bugzilla reports.
126
127 * (bug 46751) Made Buryat (Russia) (буряад) (bxr) fallback to Russian.
128
129 === Other changes in 1.22 ===
130 * redirect.php was removed. It was unused.
131 * ClickTracking integration was dropped from the mediaWiki.user.bucket
132 JavaScript function. The 'tracked' option is now ignored.
133 * BREAKING CHANGE: Legacy skins Simple, MySkin, Chick, Standard and Nostalgia
134 were all removed. (Nostalgia was moved to an extension.) The SkinLegacy and
135 LegacyTemplate classes that supported them were removed as well and are now a
136 part of the Nostalgia extension.
137 * Event namespace used by jquery.makeCollapsible has been changed from
138 'mw-collapse' to 'mw-collapsible' for consistency with the module name.
139 * BREAKING CHANGE: The "ExternalAuth" authentication subsystem was removed, along
140 with its associated globals of $wgExternalAuthType, $wgExternalAuthConf,
141 $wgAutocreatePolicy and $wgAllowPrefChange. Affected users are encouraged to
142 use AuthPlugin for external authentication/authorization needs.
143 * The Quickbar feature of the legacy skin model and the last remnants of it
144 throughout the code base have been removed.
145 * Externaledit/externaldiff preference was removed. Very few users used this
146 feature, and improper configuration can actually prevent a user from editing
147 * Calling Linker methods using a skin will now output deprecation warnings.
148 * (bug 46680) "Return to" links are no longer tagged with rel="next".
149 * BREAKING CHANGE: mw.util.tooltipAccessKeyRegexp: The match group for the
150 accesskey character is now $6 instead of $5.
151 * HipHop compiler (hphpc) support was removed. HipHop VM support (hhvm) was
152 added.
153 * A new Special:Redirect page was added, providing lookup by revision ID,
154 user ID, or file name. The old Special:Filepath page was reimplemented
155 to redirect through Special:Redirect.
156 * Monobook: Removed the old conditional stylesheets for Opera 6, 7 and 9.
157
158 == Compatibility ==
159
160 MediaWiki 1.22 requires PHP 5.3.2 or later.
161
162 MySQL is the recommended DBMS. PostgreSQL or SQLite can also be used, but
163 support for them is somewhat less mature. There is experimental support for
164 Oracle.
165
166 The supported versions are:
167
168 * MySQL 5.0.2 or later
169 * PostgreSQL 8.3 or later
170 * SQLite 3.3.7 or later
171 * Oracle 9.0.1 or later
172
173 == Upgrading ==
174
175 1.22 has several database changes since 1.21, and will not work without schema
176 updates. Note that due to changes to some very large tables like the revision
177 table, the schema update may take quite long (minutes on a medium sized site,
178 many hours on a large site).
179
180 If upgrading from before 1.11, and you are using a wiki as a commons
181 repository, make sure that it is updated as well. Otherwise, errors may arise
182 due to database schema changes.
183
184 If upgrading from before 1.7, you may want to run refreshLinks.php to ensure
185 new database fields are filled with data.
186
187 If you are upgrading from MediaWiki 1.4.x or earlier, you should upgrade to
188 1.5 first. The upgrade script maintenance/upgrade1_5.php has been removed
189 with MediaWiki 1.21.
190
191 Don't forget to always back up your database before upgrading!
192
193 See the file UPGRADE for more detailed upgrade instructions.
194
195 For notes on 1.21.x and older releases, see HISTORY.
196
197 == Online documentation ==
198
199 Documentation for both end-users and site administrators is available on
200 MediaWiki.org, and is covered under the GNU Free Documentation License (except
201 for pages that explicitly state that their contents are in the public domain):
202
203 https://www.mediawiki.org/wiki/Documentation
204
205 == Mailing list ==
206
207 A mailing list is available for MediaWiki user support and discussion:
208
209 https://lists.wikimedia.org/mailman/listinfo/mediawiki-l
210
211 A low-traffic announcements-only list is also available:
212
213 https://lists.wikimedia.org/mailman/listinfo/mediawiki-announce
214
215 It's highly recommended that you sign up for one of these lists if you're
216 going to run a public MediaWiki, so you can be notified of security fixes.
217
218 == IRC help ==
219
220 There's usually someone online in #mediawiki on irc.freenode.net.