Merge "Add support for Argon2 password hashing"
[lhc/web/wiklou.git] / RELEASE-NOTES-1.33
1 == MediaWiki 1.33 ==
2
3 THIS IS NOT A RELEASE YET
4
5 MediaWiki 1.33 is an alpha-quality branch and is not recommended for use in
6 production.
7
8 === Configuration changes in 1.33 ===
9
10 ==== New configuration ====
11 * $wgEnablePartialBlocks – This enables the Partial Blocks feature, which gives
12 accounts with block permissions the ability to block users, IPs, and IP ranges
13 from editing specific pages, while allowing them to edit the rest of the wiki.
14 * $wgMediaInTargetLanguage – whether multilingual images should be dispalyed in
15 the current parse language where available.
16
17 ==== Changed configuration ====
18 * Some external link searches will not work correctly until update.php (or
19 refreshExternallinksIndex.php) is run. These include searches for links using
20 IP addresses, internationalized domain names, and possibly mailto links.
21 * (T193868) $wgChangeTagsSchemaMigrationStage — This temporary setting, added in
22 MediaWiki 1.32, now defaults to MIGRATION_NEW instead of MIGRATION_WRITE_BOTH.
23 * Special:ActiveUsers will no longer filter out users who became inactive since
24 the last time the active users query cache was updated.
25 * If you ran migrateActors.php using an older version of MediaWiki and want to
26 run your wiki with $wgActorTableSchemaMigrationStage SCHEMA_COMPAT_READ_OLD,
27 note that log_search rows needed to find revision deletions by target user
28 were incorrectly deleted. See T215464 for details.
29
30 ==== Removed configuration ====
31 * (T199334) $wgTagStatisticsNewTable — This temporary setting, added in
32 MediaWiki 1.32, has now been removed. When loading Special:Tags, MediaWiki
33 will now always use the `change_tag_def` instead of the `change_tag` table.
34 * MediaWiki now always tidies user output, and most related
35 configuration has been removed. Thus $wgUseTidy, $wgTidyBin,
36 $wgTidyConf, $wgTidyOpts, $wgTidyInternal, and $wgDebugTidy, all
37 deprecated since 1.26, have now all been removed. The $wgTidyConfig
38 setting remains only for Remex experimental features or debugging.
39 * $wgEnableParserCache, deprecated since 1.26, was removed.
40 If disabling the parser cache is still desirable,
41 set `$wgParserCacheType = CACHE_NONE;` instead.
42 * $wgCommentTableSchemaMigrationStage has been removed. Extension code finding
43 it unset should treat it as being MIGRATION_NEW.
44
45 === New features in 1.33 ===
46 * (T96041) __EXPECTUNUSEDCATEGORY__ on a category page causes the category
47 to be hidden on Special:UnusedCategories.
48 * Add PasswordPolicy to check the password isn't in the large blacklist.
49 * The AuthManagerLoginAuthenticateAudit hook has a new parameter for
50 additional information about the authentication event.
51 * TextContent::getText() was introduced as a replacement for
52 Content::getNativeData() for text-based content models.
53 * (T210814) SVGs are now by default displayed in wiki language on image
54 pages.
55 * (T214706) LinksUpdate::getAddedExternalLinks() and
56 LinksUpdate::getRemovedExternalLinks() were introduced.
57 * Argon2 password hashing is now available, can be enabled via
58 $wgPasswordDefault = 'argon2'. It's designed to resist timing attacks
59 (requires PHP 7.2+) and GPU hacking (7.3+).
60
61 === External library changes in 1.33 ===
62
63 ==== New external libraries ====
64 * Added wikimedia/password-blacklist 0.1.4.
65 * Added guzzlehttp/guzzle 6.3.3.
66 * Added jakub-onderka/php-console-highlighter 0.3.2 explicitly (dev-only).
67
68 ==== Changed external libraries ====
69 * Updated OOUI from v0.29.2 to v0.30.2.
70 * Updated OOjs Router from pre-release to v0.2.0.
71 * Updated wikimedia/xmp-reader from 0.6.0 to 0.6.2.
72 * Updated wikimedia/scoped-callback from 2.0.0 to 3.0.0.
73 * Updated wikimedia/ip-set from 1.2.0 to 2.0.1.
74 * The deprecated IPSet\IPSet alias was removed, Wikimedia\IPSet must be
75 used instead.
76 * Updated qunitjs from 2.6.2 to 2.9.1.
77 * Updated jquery-client from 2.0.1 to 2.0.2.
78 * Updated psy/psysh from 0.9.6 to 0.9.9 (dev-only).
79 * Updated nikic/php-parser from 3.1.3 to 3.1.5 (dev-only).
80 * Updated pear/net_smtp from 1.8.0 to 1.8.1.
81 * Updated cssjanus/cssjanus from 1.2.0 to 1.2.1.
82 * Updated wikimedia/php-session-serializer from 1.0.6 to 1.0.7.
83
84 ==== Removed external libraries ====
85
86 === Bug fixes in 1.33 ===
87 * (T164211) Special:UserRights could sometimes fail with a
88 "conflict detected" error when there weren't any conflicts.
89 * (T215566) Unable to determine if the database exists
90 during a fresh installation.
91
92 === Action API changes in 1.33 ===
93 * (T198913) Added 'ApiOptions' hook.
94 * The JSON formatversion=2 is no longer experimental.
95 * Internal API errors (those with code beginning "internal_api_error") will
96 include the exception class name in a data field named "errorclass".
97 * Class names are not guaranteed to remain stable, and in particular database
98 exceptions will now include the "Wikimedia\Rdbms\" prefix in the class name.
99 * The code including an exception class name is deprecated. In the future,
100 all internal errors will use code "internal_api_error".
101 * (T212356) When using action=delete on pages with many revisions, the module
102 may return a boolean-true 'scheduled' and no 'logid'. This signifies that the
103 deletion will be processed via the job queue.
104 * action=setnotificationtimestamp will now update the watchlist asynchronously
105 if entirewatchlist is set, so updates may not be visible immediately
106 * Block info will be added to "blocked" errors from more modules.
107 * (T216245) Autoblocks will now be spread by action=edit and action=move.
108
109 === Action API internal changes in 1.33 ===
110 * A number of deprecated methods for API documentation, intended for overriding
111 by extensions, are no longer called by MediaWiki, and will emit deprecation
112 notices if your extension attempts to use them:
113 * ApiBase::getDescription() (deprecated in 1.25)
114 * ApiBase::getParamDescription() (deprecated in 1.25)
115 * ApiBase::getExamples() (deprecated in 1.25)
116 * ApiBase::getDescriptionMessage() (deprecated in 1.30)
117 Additionally, the 'APIGetDescription' and 'APIGetParamDescription' hooks have
118 been removed, as their only use was to let extensions override values returned
119 by getDescription() and getParamDescription(), respectively.
120 * API error codes may only contain ASCII letters, numbers, underscore, and
121 hyphen. Methods such as ApiBase::dieWithError() and
122 ApiMessageTrait::setApiCode() will throw an InvalidArgumentException if
123 passed a bad code.
124 * ApiBase::checkTitleUserPermissions() now takes an options array as its third
125 parameter. Passing a User object or null is deprecated.
126
127 === Languages updated in 1.33 ===
128 MediaWiki supports over 350 languages. Many localisations are updated regularly.
129 Below only new and removed languages are listed, as well as changes to languages
130 because of Phabricator reports.
131
132 * (T203908) Added language support for Eastern Pwo (kjp).
133 * (T213717) Fixed a translation error on Goan Konkani (gom-deva) translations
134 for NS_TEMPLATE.
135 * (T212221) Added $digitTransformTable for Santali (sat).
136
137 === Breaking changes in 1.33 ===
138 * The parameteter $lang in DifferenceEngine::setTextLanguage must be of type
139 Language. Other types are deprecated since 1.32.
140 * Skin::doEditSectionLink requires type Language for the parameter $lang.
141 The parameters $tooltip and $lang are mandatory. Omitting the parameters is
142 deprecated since 1.32.
143 * Language::truncate(), deprecated in 1.31, has been removed.
144 * UtfNormal, deprecated in 1.25, was removed. Use UtfNormal\Validator directly
145 instead.
146 * (T197179) In OOUI HTMLForm fields, the parameters 'notice', 'notice-messages',
147 and 'notice-message', which were deprecated in 1.32, were removed. Instead,
148 use 'help', 'help-message', and 'help-messages'.
149 * (T197179) HTMLFormField::getNotices(), deprecated in 1.32, was removed.
150 * The "Parsoid v1" compatibility mappings in ParsoidVirtualRESTService and
151 RestbaseVirtualRESTService, deprecated since 1.26, have been removed.
152 Use the RESTBase v1 or Parsoid v3 API instead.
153 * ParserOptions defaults 'tidy' to true now, since the untidy modes of the
154 parser are being deprecated and ParserOptions::getCanonicalOverrides()
155 has always been true at any rate.
156 * Support for disabling tidy and external tidy implementations has been removed.
157 This was deprecated in 1.32. The pure PHP Remex tidy implementation is now
158 used and no configuration is necessary.
159 * A number of deprecated methods for API documentation, intended for overriding
160 by extensions, are no longer called by MediaWiki, and will emit deprecation
161 notices if your extension attempts to use them:
162 * ApiBase::getDescription() (deprecated in 1.25)
163 * ApiBase::getParamDescription() (deprecated in 1.25)
164 * ApiBase::getExamples() (deprecated in 1.25)
165 * ApiBase::getDescriptionMessage() (deprecated in 1.30)
166 Additionally, the 'APIGetDescription' and 'APIGetParamDescription' hooks have
167 been removed, as their only use was to let extensions override values returned
168 by getDescription() and getParamDescription(), respectively.
169 * The authentication hooks 'AbortAutoAccount' 'AbortNewAccount', 'AbortLogin',
170 'LoginUserMigrated', 'UserCreateForm', and 'UserLoginForm', all deprecated by
171 the creation of AuthManager in 1.27, have been removed. This also means that
172 the FakeAuthTemplate and LoginForm classes are removed, that FakeAuthTemplate
173 is no longer passed into LoginSignupSpecialPage->getFieldDefinitions(), and
174 that LoginSignupSpecialPage->getBCFieldDefinitions() is removed.
175 * The 'jquery.localize' module, deprecated in 1.32, has been removed. Instead,
176 use 'jquery.i18n'.
177 * The hooks LanguageGetSpecialPageAliases and LanguageGetMagic, deprecated since
178 1.16, have now been removed. Instead, use $specialPageAliases or $magicWords
179 respectively in a $wgExtensionMessagesFiles file.
180 * The following methods of the Preferences class, deprecated in 1.31, have been
181 removed:
182 * getSaveBlacklist()
183 * loadPreferenceValues()
184 * getOptionFromUser()
185 * profilePreferences()
186 * skinPreferences()
187 * filesPreferences()
188 * datetimePreferences()
189 * renderingPreferences()
190 * editingPreferences()
191 * rcPreferences()
192 * watchlistPreferences()
193 * searchPreferences()
194 * miscPreferences()
195 * generateSkinOptions()
196 * getDateOptions()
197 * getImageSizes()
198 * getThumbSizes()
199 * validateSignature()
200 * cleanSignature()
201 * getTimezoneOptions()
202 * filterIntval()
203 * filterTimezoneInput()
204 * getTimeZoneList()
205 * mw.util.jsMessage(), deprecated in 1.20, was removed. Use mw.notify instead.
206 * (T61113) User::EDIT_TOKEN_SUFFIX was removed. It was deprecated since 1.27.
207 * The 'mediawiki.api' module aliases, deprecated in 1.32, have been removed.
208 Specifically: mediawiki.api.category, mediawiki.api.edit,
209 mediawiki.api.login, mediawiki.api.options, mediawiki.api.parse,
210 mediawiki.api.upload, mediawiki.api.user, mediawiki.api.watch,
211 mediawiki.api.messages, and mediawiki.api.rollback.
212 * The 'jquery.byteLimit' module alias for 'jquery.lengthLimit',
213 deprecated in 1.31, was removed.
214 * Revision::fetchRevision(), deprecated in 1.28, was removed.
215 * Class SquidUpdate, deprecated in 1.27, was removed.
216 * Title->getSquidURLs(), deprecated in 1.27, was removed. Instead, use
217 Title->getCdnUrls().
218 * Title::escapeFragmentForURL(), deprecated in 1.30, was removed. Use
219 Sanitizer::escapeIdForLink() or escapeIdForExternalInterwiki() instead.
220 * Title->canTalk(), deprecated in 1.30, was removed. Instead, use
221 Title->canHaveTalkPage().
222 * Title's methods for site and user page related to CSS and JS, deprecated in
223 1.31, were removed:
224 * Title->isCssOrJsPage() — Use Title->isSiteConfigPage()
225 * Title->isCssJsSubpage() – Use Title->isUserConfigPage()
226 * Title->getSkinFromCssJsSubpage() – Use Title->getSkinFromConfigSubpage()
227 * Title->isCssSubpage() – Use Title->isUserCssConfigPage()
228 * Title->isJsSubpage() – Use Title->isUserJsConfigPage()
229 * SiteSQLStore, deprecated in 1.27 and whose only method, ::newInstance(),
230 would return the global SiteStore instance, has been removed. You can get to
231 this via MediaWiki\MediaWikiServices::getInstance()->getSiteStore() directly.
232 * Linker::formatSize, deprecated in 1.28, has been removed (with DummyLinker's).
233 Instead, use Language->formatSize() with the relevant Language object.
234 * Linker::formatTemplates, deprecated in 1.28, has been removed (along with the
235 version in DummyLinker). You can use TemplatesOnThisPageFormatter directly.
236 * EventRelayerGroup::singleton(), deprecated in 1.27, has been removed. You can
237 use MediaWikiServices::getInstance()->getEventRelayerGroup() directly.
238 * LinkCache->addLink(), deprecated in 1.27, has been removed. It is thought to
239 be unused, and is distinct from OutputPage->addLink(), which remains.
240 * JsonContent->getJsonData(), deprecated in 1.25, has been removed. Instead, use
241 JsonContent->getData().
242 * MWExceptionHandler::getLogId(), deprecated in 1.27, has been removed, as the
243 exception ID is the same as the request ID, from WebRequest::getRequestId().
244 * SearchEngine::getNearMatchResultSet(), deprecated in 1.27, has been removed.
245 You can use SearchEngine::getNearMatcher() instead.
246 * EmailNotification::updateWatchlistTimestamp, deprecated in 1.27, has been
247 removed. Instead, use WatchedItemStore::updateNotificationTimestamp directly.
248 * User::getGroupName() and ::getGroupMember(), both deprecated in 1.29, have
249 been removed. Instead, please use UserGroupMembership::getGroupName() and
250 UserGroupMembership::getGroupMemberName().
251 * Backwards compatibility for setting wgSessionsInObjectCache to false or using
252 wgSessionHandler, both of which were deprecated in 1.27 with the introduction
253 of SessionManager, has been removed.
254 * SessionManager::autoCreateUser, deprecated in 1.27, has been removed. Use
255 MediaWiki\Auth\AuthManager::autoCreateUser instead.
256 * The mw.libs.jpegmeta property, deprecated in 1.31, was removed.
257 Use require( 'mediawiki.libs.jpegmeta' ) instead.
258 * The mw.user.stickyRandomId() method, deprecated in 1.32, was removed.
259 Use mw.user.getPageviewToken() instead.
260 * Removed deprecated class property WikiRevision::$importer.
261 * ResourceLoaderFileModule::readStyleFiles() now requires its $context
262 parameter.
263 * The ChangeList::insertArticleLink() method, that was deprecated in 1.27, has
264 been removed.
265 * MessageBlobStore::__construct() now requires its $rl parameter.
266
267 === Deprecations in 1.33 ===
268 * The configuration option $wgUseESI has been deprecated, and is expected
269 to be removed in a future release.
270 * The configuration option $wgSquidPurgeUseHostHeader has been deprecated,
271 and is expected to be removed in a future release.
272 * The configuration options $wgFixArabicUnicode and $wgFixMalayalamUnicode,
273 introduced in MW 1.17, have been deprecated. These fixes will always be
274 applied for Arabic and Malayalam in the future. Please enable these on
275 your local wiki (if you have them explicitly set to false) and run
276 maintenance/cleanupTitles.php to fix any existing page titles.
277 * The LegacyHookPreAuthenticationProvider class, deprecated since its creation
278 in 1.27 as part of the AuthManager re-write, now emits deprecation warnings.
279 This will help identify the issue if you added it to $wgAuthManagerConfig.
280 * wfSplitWikiId() is now deprecated. Cache key generation should have the wiki
281 domain ID as a key component and use makeGlobalKey().
282 * (T202094) Title::getUserCaseDBKey() is deprecated; instead, please use
283 Title::getDBKey(), which doesn't vary case.
284 * User::getPasswordValidity() is now deprecated. User::checkPasswordValidity()
285 returns the same information in a more useful format.
286 * For Linker::generateTOC() and Linker::tocList(), passing strings or booleans
287 as the $lang parameter was deprecated. The same applies to DummyLinker.
288 * The PasswordPolicy 'PasswordCannotBePopular' has been deprecated. To
289 follow best practices, it is reccommended to use 'PasswordNotInLargeBlacklist'
290 instead which blacklists 100,000 commonly used passwords.
291 * (T208862) Action::requiresUnblock() is now called from
292 Title::getUserPermissionsErrors() and Title::userCan(). Previously, the method
293 was only called in Action::checkCanExecute(). Actions should ensure that their
294 requiresUnblock() returns the proper result (the default is `true`).
295 * (T211608) The MediaWiki\Services namespace has been renamed to
296 Wikimedia\Services. The old name is still supported, but deprecated.
297 * (T155582) Content::getNativeData has been deprecated. Please use model-
298 specific getters, such as TextContent::getText().
299 * The class WebInstallerOutput is now marked as @private.
300 * (T209699) The jquery.async module has been deprecated. JavaScript code that
301 needs asynchronous behaviour should use Promises.
302 * Password::equals() is deprecated, use verify().
303 * BaseTemplate::msgWiki() and QuickTemplate::msgWiki() will be removed. Use
304 other means to fetch a properly escaped message string or Message object.
305 * (T126091) The 'ResourceLoaderTestModules' hook, which lets you declare QUnit
306 testing code for your JavaScript modules, is deprecated. Instead, you can now
307 use the new extension registration key 'QUnitTestModule'.
308 * (T213426) The jquery.throttle-debounce module has been deprecated. JavaScript
309 code that needs this behaviour should use OO.ui.debounce/throttle.
310 * The mw.language.specialCharacters property from the
311 'mediawiki.language.specialCharacters' module has been deprecated.
312 Use require( 'mediawiki.language.specialCharacters' ) instead.
313 * ChangeTags::purgeTagUsageCache() has been deprecated, and is expected to be
314 removed in a future release.
315 * Passing a User object or null as the third parameter to
316 ApiBase::checkTitleUserPermissions() has been deprecated. Pass an array
317 [ 'user' => $user ] instead.
318
319 === Other changes in 1.33 ===
320 * (T201747) Html::openElement() warns if given an element name with a space
321 in it.
322 * The implementation of buildStringCast() in Wikimedia\Rdbms\Database has
323 changed to explicitly cast. Subclasses relying on the base-class
324 implementation should check whether they need to override it now.
325
326 == Compatibility ==
327 MediaWiki 1.33 requires PHP 7.0.13 or later. Although HHVM 3.18.5 or later is
328 supported, it is generally advised to use PHP 7.0.13 or later for long term
329 support.
330
331 MySQL/MariaDB is the recommended DBMS. PostgreSQL or SQLite can also be used,
332 but support for them is somewhat less mature. There is experimental support for
333 Oracle and Microsoft SQL Server.
334
335 The supported versions are:
336
337 * MySQL 5.5.8 or later
338 * PostgreSQL 9.2 or later
339 * SQLite 3.3.7 or later
340 * Oracle 9.0.1 or later
341 * Microsoft SQL Server 2005 (9.00.1399)
342
343 == Upgrading ==
344 1.33 has several database changes since 1.32, and will not work without schema
345 updates. Note that due to changes to some very large tables like the revision
346 table, the schema update may take quite long (minutes on a medium sized site,
347 many hours on a large site).
348
349 Don't forget to always back up your database before upgrading!
350
351 See the file UPGRADE for more detailed upgrade instructions, including
352 important information when upgrading from versions prior to 1.11.
353
354 For notes on 1.32.x and older releases, see HISTORY.
355
356 == Online documentation ==
357 Documentation for both end-users and site administrators is available on
358 MediaWiki.org, and is covered under the GNU Free Documentation License (except
359 for pages that explicitly state that their contents are in the public domain):
360
361 https://www.mediawiki.org/wiki/Special:MyLanguage/Documentation
362
363 == Mailing list ==
364 A mailing list is available for MediaWiki user support and discussion:
365
366 https://lists.wikimedia.org/mailman/listinfo/mediawiki-l
367
368 A low-traffic announcements-only list is also available:
369
370 https://lists.wikimedia.org/mailman/listinfo/mediawiki-announce
371
372 It's highly recommended that you sign up for one of these lists if you're
373 going to run a public MediaWiki, so you can be notified of security fixes.
374
375 == IRC help ==
376 There's usually someone online in #mediawiki on irc.freenode.net.