Add Special:ApiSandbox
[lhc/web/wiklou.git] / RELEASE-NOTES-1.27
1 Security reminder: If you have PHP's register_globals option set, you must
2 turn it off. MediaWiki will not work with it enabled.
3
4 == MediaWiki 1.27 ==
5
6 THIS IS NOT A RELEASE YET
7
8 MediaWiki 1.27 is an alpha-quality branch and is not recommended for use in
9 production.
10
11 === Configuration changes in 1.27 ===
12 * $wgUseLinkNamespaceDBFields was removed.
13 * Deprecated $wgResourceLoaderMinifierStatementsOnOwnLine and
14 $wgResourceLoaderMinifierMaxLineLength, because there was little value in
15 making the behavior configurable. The default values (`false` for the former,
16 1000 for the latter) are now hard-coded.
17 * $wgDebugDumpSqlLength was removed (deprecated in 1.24).
18 * $wgDebugDBTransactions was removed (deprecated in 1.20).
19 * $wgUseXVO has been removed, as it provides functionality only used by
20 custom Wikimedia patches against Squid 2.x that probably noone uses in
21 production anymore. There is now $wgUseKeyHeader that provides similar
22 functionality but instead of the MediaWiki-specific X-Vary-Options header,
23 uses the draft Key header standard.
24 * $wgScriptExtension (and support for '.php5' entry points) was removed. See the
25 deprecation notice in the release notes for version 1.25 for advice on how to
26 preserve support for '.php5' entry points via URL rewriting.
27 * Password handling via the User object has been deprecated and partially
28 removed, pending the future introduction of AuthManager. In particular:
29 ** expirePassword(), getPasswordExpireDate(), resetPasswordExpiration(), and
30 getPasswordExpired() have been removed. They were unused outside of core.
31 ** The mPassword, mNewpassword, mNewpassTime, and mPasswordExpires fields are
32 now private and will be removed in the future.
33 ** The getPassword() and getTemporaryPassword() methods now throw
34 BadMethodCallException and will be removed in the future.
35 ** The ability to pass 'password' and 'newpassword' to createNew() has been
36 removed. The only users of it seem to have been using it to set invalid
37 passwords, and so shouldn't be greatly affected.
38 ** setPassword(), setInternalPassword(), and setNewpassword() have been
39 deprecated, pending the introduction of AuthManager.
40 ** User::randomPassword() is deprecated in favor of a new method
41 PasswordFactory::generateRandomPasswordString()
42 ** User::getPasswordFactory() is deprecated, callers should just create a
43 PasswordFactory themselves.
44 ** A new constructor, User::newSystemUser(), has been added to simplify the
45 creation of passwordless "system" users for logged actions.
46 * $wgMaxSquidPurgeTitles was removed.
47 * $wgAjaxWatch was removed. This is now enabled by default.
48 * $wgUseInstantCommons now hotlinks Commons images by default instead of
49 downloading originals and thumbnailing them locally. This allows wikis to save
50 on CPU and bandwidth while reducing time to first byte for pages, even without
51 a thumbnail handler. See $wgForeignFileRepos documentation for tweaks.
52 * (T27397) WebP is enabled by default as an uploadable filetype.
53 * (T48998) $wgArticlePath must now be either a full url, or start with a "/".
54 * $wgRateLimitLog was removed; use $wgDebugLogGroups['ratelimit'] instead.
55 * Deprecated API formats dbg, txt, and yaml have been removed.
56 * CLDRPluralRule* classes have been replaced with
57 wikimedia/cldr-plural-rule-parser.
58 * Removed $wgProfilePerHost, $wgUDPProfilerHost, $wgUDPProfilerPort,
59 $wgUDPProfilerFormatString, $wgStatsMethod, $wgAggregateStatsID,
60 $wgStatsFormatString, and $wgProfileCallTree (deprecated since 1.20).
61 * For proper operation of LocalIdLookup with shared user tables, ensure that
62 $wgSharedDB and $wgSharedTables are properly set even on the "central" wiki
63 that all others are sharing from and that $wgLocalDatabases is set to the
64 full list of sharing wikis on all those wikis.
65 * $wgAllowAsyncCopyUploads and $CopyUploadAsyncTimeout were removed. This was an
66 experimental feature that has never worked.
67 * $wgEnotifUseJobQ was removed and the job queue is always used.
68 * The functionality of the ApiSandbox extension has been merged into core. The
69 extension should no longer be used.
70
71 === New features in 1.27 ===
72 * $wgDataCenterUpdateStickTTL was also added. This decides how long a user
73 sticks to the primary DC (via cookies) after they make changes to the site.
74 * Added a new hook, 'UserMailerTransformContent', to transform the contents
75 of an email. This is similar to the EmailUser hook but applies to all mail
76 sent via UserMailer.
77 * Added a new hook, 'UserMailerTransformMessage', to transform the contents
78 of an emai after MIME encoding.
79 * Added a new hook, 'UserMailerSplitTo', to control which users have to be
80 emailed separately (ie. there is a single address in the To: field) so
81 user-specific changes to the email can be applied safely.
82 * $wgCdnMaxageLagged was added, which limits the CDN cache TTL
83 when any load balancer uses a DB that is lagged beyond the 'max lag'
84 setting in the relevant section of $wgLBFactoryConf.
85 * User::newSystemUser() may be used to simplify the creation of passwordless
86 "system" users for logged actions from scripts and extensions.
87 * Extensions can now return detailed error information via the API when
88 preventing user actions using 'getUserPermissionsErrors' and similar hooks
89 by using ApiMessage instances instead of strings for the $result value.
90 * $wgAPIMaxLagThreshold was added to limit bot changes when databases lag
91 becomes too high.
92 * Skins and extensions can now use FlexBox mixins (.flex-display(@display: flex)
93 and .flex(@grow: 1, @shrink: 1, @width: auto, @order: 1)) in Less to create
94 cross-browser-compatible FlexBox rules. Users will still need to add fallback
95 float rules or the like for compatibility with IE9- separately.
96 * Added MWTimestamp::getTimezoneString() which returns the localized timezone
97 string, if available. To localize this string, see the comments of
98 $wgLocaltimezone in includes/DefaultSettings.php.
99 * Added CentralIdLookup, a service that allows extensions needing a concept of
100 "central" users to get that without having to know about specific central
101 authentication extensions.
102 * $wgMaxUserDBWriteDuration added to limit huge user-generated transactions.
103 Regular web request transactions that takes longer than this are aborted.
104 * Added a new hook, 'TitleMoveCompleting', which runs before a page move is
105 committed.
106 * $wgCdnReboundPurgeDelay was added to provide secondary delayed purges of URLs
107 from CDN to mitigate DB replication lag and WAN cache purge lag.
108 * (T49162) Installer will default to setting CACHE_ACCEL as the main cache type
109 if it is available.
110 * It is now possible to patrol file uploads (both for new files and new versions
111 of existing files). Special:NewFiles has gained an option to filter by patrol
112 status. This functionality can be disabled using $wgUseFilePatrol.
113 * Added MWGrants and associated configuration settings $wgGrantPermissions and
114 $wgGrantPermissionGroups to hold configuration for authentication features
115 such as OAuth that want to allow restricting the user rights a user may make
116 use of.
117 ** If you're already using the OAuth extension, these new variables are
118 identical to (and will replace) $wgMWOAuthGrantPermissions and
119 $wgMWOAuthGrantPermissionGroups.
120 * Added MWRestrictions as a class to check restrictions on a WebRequest, e.g.
121 to assert that the request comes from a particular IP range.
122 * Whitelisted the following HTML attributes for all elements in wikitext:
123 aria-describedby, aria-flowto, aria-label, aria-labelledby, aria-owns.
124 * Removed "presentation" restriction on the HTML role attribute in wikitext.
125 All values are now allowed for the role attribute.
126
127 === External library changes in 1.27 ===
128
129 ==== Upgraded external libraries ====
130 * Updated oojs/oojs-ui from v0.12.12 to v0.13.3.
131 * Updated composer/semver from v1.0.0 to v1.2.0.
132 * Update liuggio/statsd-php-client to 1.0.18.
133
134 ==== New external libraries ====
135 * Added wikimedia/base-convert v1.0.1.
136 * Added wikimedia/cldr-plural-rule-parser v1.0.0.
137 * Added wikimedia/relpath v1.0.3.
138 * Added wikimedia/running-stat v1.1.0.
139
140 ==== Removed and replaced external libraries ====
141
142 === Bug fixes in 1.27 ===
143 * Special:Upload will now display correct maximum allowed file size when running
144 under HHVM (T116347).
145
146 === Action API changes in 1.27 ===
147 * Added list=allrevisions.
148 * generator=recentchanges now has the option to generate revids.
149 * ApiPageSet::setRedirectMergePolicy() was added. This allows generator
150 modules to define how generator data for a redirect source gets merged
151 into the redirect destination.
152 * prop=imageinfo&iiprop=uploadwarning will no longer include the possibility of
153 "was-deleted" warning.
154 * Added difftotextpst to query=revisions which preforms a pre-save transform on
155 the text before diffing it.
156 * Deprecated formats dbg, txt, and yaml have been removed.
157 * (T47988) The protect log event details now use new-style formatting.
158 * The following response properties from action=login are deprecated, and may
159 be removed in the future: lgtoken, cookieprefix, sessionid. Clients should
160 handle cookies to properly manage session state.
161 * action=upload no longer understands statuskey, asyncdownload or leavemessage.
162
163 === Action API internal changes in 1.27 ===
164 * ApiQueryORM removed.
165 * The following classes have been removed:
166 ** ApiFormatDbg
167 ** ApiFormatTxt
168 ** ApiFormatYaml
169 * ApiQueryBase::titleToKey(), ApiQueryBase::keyToTitle() and
170 ApiQueryBase::keyPartToTitle() all removed (deprecated since 1.24).
171 * ApiQueryBase::checkRowCount() was removed (deprecated since 1.24).
172 * ApiQueryBase::getDirectionDescription() was removed (deprecated since 1.25).
173 * ApiQuery::getModules() was removed (deprecated since 1.21).
174 * ApiMain::getModules() was removed (deprecated since 1.21).
175 * ApiBase::getVersion() was removed (deprecated since 1.21).
176
177 === Languages updated in 1.27 ===
178
179 MediaWiki supports over 350 languages. Many localisations are updated
180 regularly. Below only new and removed languages are listed, as well as
181 changes to languages because of Phabricator reports.
182
183 * (T113688) Change default numerals from Gurmukhi to Arabic for Punjabi locale.
184
185 === Other changes in 1.27 ===
186 * ProfilerOutputUdp was removed. Note that there is a ProfilerOutputStats class.
187 * WikiPage::doDeleteArticleReal() and WikiPage::doDeleteArticle() now
188 ignore the 2nd and 3rd arguments (formerly $id and $commit).
189 * Removed "loaderScripts" option from ResourceLoaderFileModule class.
190 * Removed ORM-like wrapper added in 1.20.
191 * LinkCache::getGoodLinks and LinkCache::getBadLinks were removed
192 (deprecated in 1.26).
193 * WikiPage::doQuickEdit() was removed (deprecated since 1.21).
194 * Removed SiteObject and SiteArray classes (deprecated in 1.21).
195 * MessageBlobStore::getInstance() was removed (deprecated since 1.25).
196 * (T84937) Free external links ("autolinked" urls) will now be terminated
197 by &nbsp; and HTML entity encodings of &nbsp, <, and >.
198 * (T36948) The default file revert message's timestamp is now in
199 $wgLocaltimezone, instead of UTC.
200 * The default name of the 'suppress' group page has been changed from
201 'Project:Oversight' to 'Project:Suppress'.
202 * DatabaseBase::resultObject() is now protected (use outside Database classes
203 not necessary since 1.11).
204 * Calling ResourceLoaderFileModule::readStyleFiles() without a
205 ResourceLoaderContext instance is deprecated.
206 * ResourceLoader::getLessCompiler() now takes an optional parameter of
207 additional LESS variables to set for the compiler.
208 * wfBaseConvert() marked as deprecated, use Wikimedia\base_convert() directly
209 instead.
210 * Obsolete maintenance scripts clearCacheStats.php and showCacheStats.php
211 were removed. The underlying data is sent to StatsD (see $wgStatsdServer).
212 * Removed msg_resource_links database table and associated code.
213 * Removed msg_resource database table and associated code.
214 * Skin::getNamespaceNotice() was removed.
215 * wfIsConfiguredProxy() was removed (deprecated since 1.24).
216 * wfDebugTimer() was removed (deprecated since 1.25).
217 * wfIsTrustedProxy() was removed (deprecated since 1.24).
218 * wfGetIP() was removed (deprecated since 1.19).
219 * MWHookException was removed.
220 * OutputPage::appendSubtitle() was removed (deprecated since 1.19).
221 * OutputPage::loginToUse() was removed (deprecated since 1.19).
222 * Article::loadContent() was removed (deprecated since 1.19).
223 * User::editToken() was removed (deprecated since 1.19).
224 * Removed --force-normal option of dumpBackup.php, as it no longer served
225 any useful purpose since 1.22.
226 * The functions processOption() and processArgs() on the BackupDumper and
227 TextPassDumper classes have been removed.
228 * The maintenance/backupTextPass.inc file was deleted. You should include
229 maintenance/dumpTextPass.php instead.
230 * WikiPage::getUsedTemplates() was removed (deprecated since 1.19).
231 * wfEmptyMsg() was removed (deprecated since 1.18).
232 * OutputPage::permissionRequired() was removed (deprecated since 1.18).
233 * OutputPage::blockedPage() was removed (deprecated since 1.18).
234 * User::getSkin() was removed (deprecated since 1.18).
235 * OutputPage::includeJQuery() was removed (deprecated since 1.17).
236 * WikiPage::updateRestrictions() was removed (deprecated since 1.19).
237 * WikiPage::testPreSaveTransform() was removed (deprecated since 1.19).
238 * LogPage::logName() was removed (deprecated since 1.19).
239 * LogPage::logHeader() was removed (deprecated since 1.19).
240 * wfCheckLimits() was removed (deprecated since 1.24).
241 * Linker::makeKnownLinkObj() was removed (deprecated since 1.16).
242 * Linker::makeLinkObj() was removed (deprecated since 1.16).
243 * wfMsgForContentNoTrans() was removed (deprecated since 1.18).
244 * ChangesList::usePatrol was removed (deprecated since 1.22).
245 * wfMsgNoTrans() was removed (deprecated since 1.18).
246 * Linker::makeImageLink2 was removed (deprecated since 1.20).
247 * Title::userIsWatching() was removed (deprecated since 1.20).
248 * Removed WaitForSlave maintenance script; use SELECT MASTER_POS_WAIT()
249 database function directly instead.
250 * wfMsg() was removed (deprecated since 1.18).
251 * wfMsgForContent() was removed (deprecated since 1.18).
252 * wfMsgReal() was removed (deprecated since 1.18).
253 * wfMsgGetKey() was removed (deprecated since 1.18).
254 * wfMsgHtml() was removed (deprecated since 1.18).
255 * wfMsgWikiHtml() was removed (deprecated since 1.18).
256 * wfMsgExt() was removed (deprecated since 1.18).
257 * Language::armourMath() was removed (deprecated since 1.22).
258 * LanguageConverter::armourMath() was removed (deprecated since 1.22).
259 * FakeConverter::armourMath() was removed (deprecated since 1.22).
260 * The unused jquery.validate ResourceLoader module was removed.
261 * FileRepo::getRootUrl() was removed (deprecated since 1.20).
262 * User::generateToken() was removed (deprecated since 1.20).
263 * WikiPage::getRawText() was removed (deprecated since 1.21).
264 * ParserOutput::hasCustomDataUpdates() was removed (deprecated since 1.25).
265 * ParserOutput::addSecondaryDataUpdate() was removed (deprecated since 1.25).
266 * ParserOutput::getSecondaryDataUpdates() was removed (deprecated since 1.25).
267 * Gallery images with multiple caption pipes no longer concatenate them all
268 together but instead pick the final one, similar to image syntax.
269 * XML-like parser tags (such as <gallery>), when unclosed, will be left unparsed
270 rather than consume everything until the end of the page.
271 * New maintenance script resetUserEmail.php allows sysadmins to reset user emails in case
272 a user forgot password/account was stolen.
273
274 == Compatibility ==
275
276 MediaWiki 1.27 requires PHP 5.3.3 or later. There is experimental support for
277 HHVM 3.6.5 or later.
278
279 MySQL is the recommended DBMS. PostgreSQL or SQLite can also be used, but
280 support for them is somewhat less mature. There is experimental support for
281 Oracle and Microsoft SQL Server.
282
283 The supported versions are:
284
285 * MySQL 5.0.3 or later
286 * PostgreSQL 8.3 or later
287 * SQLite 3.3.7 or later
288 * Oracle 9.0.1 or later
289 * Microsoft SQL Server 2005 (9.00.1399)
290
291 == Upgrading ==
292
293 1.27 has several database changes since 1.26, and will not work without schema
294 updates. Note that due to changes to some very large tables like the revision
295 table, the schema update may take quite long (minutes on a medium sized site,
296 many hours on a large site).
297
298 If upgrading from before 1.11, and you are using a wiki as a commons
299 repository, make sure that it is updated as well. Otherwise, errors may arise
300 due to database schema changes.
301
302 If upgrading from before 1.7, you may want to run refreshLinks.php to ensure
303 new database fields are filled with data.
304
305 If you are upgrading from MediaWiki 1.4.x or earlier, you should upgrade to
306 1.5 first. The upgrade script maintenance/upgrade1_5.php has been removed
307 with MediaWiki 1.21.
308
309 Don't forget to always back up your database before upgrading!
310
311 See the file UPGRADE for more detailed upgrade instructions.
312
313 For notes on 1.26.x and older releases, see HISTORY.
314
315 == Online documentation ==
316
317 Documentation for both end-users and site administrators is available on
318 MediaWiki.org, and is covered under the GNU Free Documentation License (except
319 for pages that explicitly state that their contents are in the public domain):
320
321 https://www.mediawiki.org/wiki/Documentation
322
323 == Mailing list ==
324
325 A mailing list is available for MediaWiki user support and discussion:
326
327 https://lists.wikimedia.org/mailman/listinfo/mediawiki-l
328
329 A low-traffic announcements-only list is also available:
330
331 https://lists.wikimedia.org/mailman/listinfo/mediawiki-announce
332
333 It's highly recommended that you sign up for one of these lists if you're
334 going to run a public MediaWiki, so you can be notified of security fixes.
335
336 == IRC help ==
337
338 There's usually someone online in #mediawiki on irc.freenode.net.