X-Git-Url: http://git.heureux-cyclage.org/?a=blobdiff_plain;f=HISTORY;h=0ec09c08712d43fb614339f9e1ef3a1c7f096923;hb=88fd6d25aba7037e780fd88fd4f684f0f6501de2;hp=8cd36ec96e557269e2a33752fc91fe36a64a8e13;hpb=dd8f9c128aa10b7a31d6bbabe8dc79a2440b86f6;p=lhc%2Fweb%2Fwiklou.git diff --git a/HISTORY b/HISTORY index 8cd36ec96e..0ec09c0871 100644 --- a/HISTORY +++ b/HISTORY @@ -19,8 +19,6 @@ Change notes from older releases. For current info see RELEASE-NOTES. * Subpages are now enabled in the MediaWiki namespace by default. This is mainly a cosmetic change, and does not in any way affect the MessageCache, which was already effectively treating the namespace as if it had subpages. -* (bug 10837) $wgVariant is a user variant selected in the user's preferences - if the $wgContLang does not have variant, then the $wgLang is used instead. * Oracle: maintenance/ora/user.sql script for creating DB user on oracle with appropriate privileges. Creating this user with web-install page requires oci8.privileged_connect set to On in php.ini. @@ -194,10 +192,7 @@ Change notes from older releases. For current info see RELEASE-NOTES. * The default output format is now HTML 5 instead of XHTML 1.0 Transitional. This can be disabled by setting $wgHtml5 = false;. Specific features enabled if HTML 5 is used: -** New HTML 5 input attributes allow JavaScript-free input validation in some - cutting-edge browsers. E.g., some inputs will be autofocused, users will - not be allowed to submit forms with certain types of invalid values (like - numbers outside the permitted ranges), etc. +** Some extra inputs will be autofocused, in supporting browsers. ** The summary attribute has been removed from tables of contents. summary is obsolete in HTML 5 and wasn't useful here anyway. ** Unnecessary type="" attribute removed for CSS and JS. @@ -745,6 +740,9 @@ comment from another wiki. * (bug 22551) Special:Resetpass now has a "Cancel" button that sends the user to the page set in the &returnto parameter. * (bug 19194) Search box in Modern skin doesn't focus with Safari/Chrome +* (bug 17790) Users instantly logged off on HughesNet +* (bug 21549) Make foreign key constraints DEFERRABLE INITIALLY DEFERRED + when using Postgres as the database backend. == API changes in 1.16 == @@ -1154,6 +1152,11 @@ changes to languages because of MediaZilla reports. * (bug 17241) The diffonly URI parameter should cascade to "Next edit" and "Previous edit" diff links * (bug 16823) 'Sidebar search form should not use Special:Search view URL as target' * (bug 16343) Non-existing, but in use, category pages can be "go" match hits +* Fixed a CSS validation issue which allowed external images to be included + into wikis where that is disallowed by configuration. +* Fixed a data leakage vulnerability for private wikis using img_auth.php or + similar image access authentication schemes. Check user permissions before + streaming out scaled images from thumb.php. == API changes in 1.15 == * (bug 16858) Revamped list=deletedrevs to make listing deleted contributions