resources: Collapse all jQuery UI modules into one deprecated mega-module
[lhc/web/wiklou.git] / HISTORY
1 Change notes from older releases. For current info see RELEASE-NOTES-1.34.
2
3 = MediaWiki 1.33 =
4
5 === Upgrading notes for 1.33 ===
6 1.33 has several database changes since 1.32, and will not work without schema
7 updates. Note that due to changes to some very large tables like the revision
8 table, the schema update may take quite long (minutes on a medium sized site,
9 many hours on a large site).
10
11 Don't forget to always back up your database before upgrading!
12
13 See the file UPGRADE for more detailed upgrade instructions, including
14 important information when upgrading from versions prior to 1.11.
15
16 Some specific notes for MediaWiki 1.33 upgrades are below:
17
18 * Some external link searches will not work correctly until update.php (or
19 refreshExternallinksIndex.php) is run. These include searches for links using
20 IP addresses, internationalized domain names, and possibly mailto links.
21 * If you ran migrateActors.php using an older version of MediaWiki and want to
22 run your wiki with $wgActorTableSchemaMigrationStage SCHEMA_COMPAT_READ_OLD,
23 note that log_search rows needed to find revision deletions by target user
24 were incorrectly deleted. See T215464 for details.
25 * If revision deletions were performed when the wiki was configured with
26 $wgActorTableSchemaMigrationStage SCHEMA_COMPAT_WRITE_BOTH and without
27 migrateActors.php having been run, the log_search table may contain rows with
28 empty values for "target_author_actor" which will prevent log searches for
29 revision deletions by target user from finding those log entries. These rows
30 may be corrected by (re-)running migrateActors.php.
31
32 For notes on 1.32.x and older releases, see HISTORY.
33
34 == MediaWiki 1.33.0 ==
35
36 === Changes since MediaWiki 1.33.0-rc.0 ===
37 * (T225558) Update installer link to PHP intl.
38 * (T225901) Only attempt to deduplicate if there is data in archive and revision
39 tables.
40 * (T225564) Fetch tag ID before calling undefineTag().
41 * (T225496) Detect APC for MainCacheType in CLI installer.
42 * Call unpack() with correct parameters in MimeAnalyzer.php for PHP 7.0 support.
43 * (T212613) Style change tags correctly on Special:Newpages.
44 * (T202211) Fix SQLite patch-(page|template)links-fix-pk.sql column order.
45
46 == MediaWiki 1.33.0-rc.0 ==
47
48 === Configuration changes for system administrators in 1.33 ===
49 ==== New configuration ====
50 * $wgEnablePartialBlocks – This enables the Partial Blocks feature, which gives
51 accounts with block permissions the ability to block users, IPs, and IP ranges
52 from editing specific pages, while allowing them to edit the rest of the wiki.
53 It is a temporary setting for gradual enablement, current default to `false`,
54 and will be set to `true` and then removed once initial development completes.
55
56 ==== Changed configuration ====
57 * $wgChangeTagsSchemaMigrationStage (T193868) — This temporary setting, added in
58 MediaWiki 1.32, now defaults to MIGRATION_NEW instead of MIGRATION_WRITE_BOTH.
59 * $wgPasswordPolicy – There is a new password policy to check that the account's
60 password is not in the large blacklist. This is enabled by default for the
61 built-in user groups bureaucrat, sysop, interface-admin, and bot. To configure
62 this for other user groups, set the `PasswordNotInLargeBlacklist` flag `true`.
63 * $wgPasswordDefault – There is a new password type configuration using Argon2
64 password hashing (which requires PHP 7.2 and above). It's designed to resist
65 timing attacks, and (on systems with PHP 7.3+) GPU hacking; if you configure
66 argon2 to be used, by default, it will automatically choose the best available
67 algorithm depending on which version of PHP you have available. To use this,
68 you can set `$wgPasswordDefault = 'argon2';`.
69 * $wgActorTableSchemaMigrationStage now defaults to reading the new schema.
70 update.php will back-populate the new database fields due to the changed
71 setting, which may take some time on large wikis. You can avoid downtime by
72 following a process like that described in T188327.
73
74 ==== Removed configuration ====
75 * $wgTagStatisticsNewTable (T199334) — This temporary setting, added in
76 MediaWiki 1.32, has now been removed. When loading Special:Tags, MediaWiki
77 will now always use the `change_tag_def` instead of the `change_tag` table.
78 * $wgUseTidy, $wgTidyBin, $wgTidyConf, $wgTidyOpts, $wgTidyInternal, and
79 $wgDebugTidy – These options, all deprecated since 1.26, have now all been
80 removed, as MediaWiki now always tidies user output. The $wgTidyConfig setting
81 remains only for experimental features and debugging, and should not be used.
82 * $wgEnableParserCache – This setting has been deprecated since 1.26, has now
83 been removed. If you still desire to disable the parser cache, instead you can
84 set `$wgParserCacheType = CACHE_NONE;`.
85 * $wgCommentTableSchemaMigrationStage – This temporary migration setting has now
86 been removed. Code finding it unset should treat it as being MIGRATION_NEW.
87 * $wgAuth – This old setting, deprecated in 1.27, has been removed as part of
88 the removal of AuthPlugin.
89 * $wgSitesCacheFile – This configuration was introduced in 1.25 with the intent
90 to allow sites to configure a file in which to cache the SiteStore database
91 table, but it was never used. SiteStore already caches its information by
92 default using BagOStuff (e.g. Memcached or APC).
93 * $wgClockSkewFudge – This setting was used by User.php to let sites adjust by
94 how much MediaWiki would fudge when trying to minimize the chances of a
95 user.user_touched database update to the "current" timestamp being before the
96 value already there (e.g. due to clock skew between different servers). This
97 is no longer a problem, because the code now ensures the timestamp is always
98 higher than the previous one. The writes are guarded with CAS logic (check
99 and set), which prevents updates that would overlap.
100 * $wgDBmysql5 (T196185) - This experimental setting, deprecated in 1.31, has
101 been removed.
102
103 === New user-facing features in 1.33 ===
104 * (T96041) __EXPECTUNUSEDCATEGORY__ on a category page causes the category
105 to be hidden on Special:UnusedCategories.
106 * (T210814) SVGs are now by default displayed in wiki language on image
107 pages.
108 * Special:CreateAccount now warns the user if their chosen username has to be
109 normalized.
110 * (T205040) Multilingual images are now be displayed in the current parse
111 language where available.
112 * Special:ActiveUsers will no longer filter out users who became inactive since
113 the last time the active users query cache was updated.
114 * (T215675) RecentChange and ManualLogEntry implement new Taggable interface.
115 * (T215675) Added a hook, ManualLogEntryBeforePublish, to allow extensions
116 to modify (example: add tags) log entries.
117
118 === New developer features in 1.33 ===
119 * The AuthManagerLoginAuthenticateAudit hook has a new parameter for
120 additional information about the authentication event.
121 * TextContent::getText() was introduced as a replacement for
122 Content::getNativeData() for text-based content models.
123 * (T214706) LinksUpdate::getAddedExternalLinks() and
124 LinksUpdate::getRemovedExternalLinks() were introduced.
125 * (T213893) Added 'MaintenanceUpdateAddParams' hook
126 * (T219655) The MarkPatrolled hook has a new parameter for the tags
127 associated with this entry in the patrol log.
128 * (T212472) Extensions can now specify platform abilities they require to work,
129 limited to shell access for now.
130
131
132 === External library changes in 1.33 ===
133 ==== New external libraries ====
134 * Added wikimedia/password-blacklist 0.1.4.
135 * Added guzzlehttp/guzzle 6.3.3.
136
137 ==== Changed external libraries ====
138 * Updated OOUI from v0.29.2 to v0.31.3.
139 * Updated OOjs Router from pre-release to v0.2.0.
140 * Updated moment from v2.19.3 to v2.24.0.
141 * Updated wikimedia/xmp-reader from 0.6.0 to 0.6.2.
142 * Updated wikimedia/scoped-callback from 2.0.0 to 3.0.0.
143 * Updated jquery-client from 2.0.1 to 2.0.2.
144 * Updated pear/net_smtp from 1.8.0 to 1.8.1.
145 * Updated cssjanus/cssjanus from 1.2.0 to 1.3.0.
146 * Updated wikimedia/php-session-serializer from 1.0.6 to 1.0.7.
147
148 ==== Removed external libraries ====
149 * (T219403) jquery.ui.spinner, deprecated since 1.31, was removed.
150
151
152 === Developer library changes in 1.33 ===
153 ==== New developer libraries ====
154 * Added jakub-onderka/php-console-highlighter 0.3.2 explicitly (dev-only).
155 * Added mediawiki/mediawiki-phan-config 0.5.0 (dev-only).
156
157 ==== Changed developer libraries ====
158 * Updated wikimedia/ip-set from 1.3.0 to 2.0.1.
159 * The deprecated IPSet\IPSet alias was removed, Wikimedia\IPSet must be
160 used instead.
161 * Updated psy/psysh from 0.9.6 to 0.9.9 (dev-only).
162 * Updated nikic/php-parser from 3.1.3 to 3.1.5 (dev-only).
163 * Updated mediawiki/mediawiki-codesniffer from 22.0.0 to 25.0.0 (dev-only).
164 * Updated qunitjs from 2.6.2 to 2.9.1.
165
166 ==== Removed developer libraries ====
167 * The jetbrains/phpstorm-stubs repository was removed in favour of the minimal
168 stubs we need, which are kept in the new `.phan/internal_stubs` directory
169 (dev-only).
170
171
172 === Bug fixes in 1.33 ===
173 * (T164211) Special:UserRights could sometimes fail with a
174 "conflict detected" error when there weren't any conflicts.
175 * (T216029) Chrome redirects to Special:BadTitle after editing a section with
176 a non-Latin name on a page with non-Latin characters in title.
177 * (T222385) resourceloader: Use AND instead of OR for upsert conds in
178 saveFileDependencies().
179
180 === Action API changes in 1.33 ===
181 * (T198913) Added 'ApiOptions' hook.
182 * The JSON formatversion=2 is no longer experimental.
183 * Internal API errors (those with code beginning "internal_api_error") will
184 include the exception class name in a data field named "errorclass".
185 * Class names are not guaranteed to remain stable, and in particular database
186 exceptions will now include the "Wikimedia\Rdbms\" prefix in the class name.
187 * The code including an exception class name is deprecated. In the future,
188 all internal errors will use code "internal_api_error".
189 * (T212356) When using action=delete on pages with many revisions, the module
190 may return a boolean-true 'scheduled' and no 'logid'. This signifies that the
191 deletion will be processed via the job queue.
192 * action=setnotificationtimestamp will now update the watchlist asynchronously
193 if entirewatchlist is set, so updates may not be visible immediately
194 * Block info will be added to "blocked" errors from more modules.
195 * (T216245) Autoblocks will now be spread by action=edit and action=move.
196 * action=query&meta=userinfo has a new uiprop, 'latestcontrib', that returns
197 the date of user's latest contribution.
198 * (T25227) action=logout now requires to be posted and have a csrf token.
199
200 === Action API internal changes in 1.33 ===
201 * A number of deprecated methods for API documentation, intended for overriding
202 by extensions, are no longer called by MediaWiki, and will emit deprecation
203 notices if your extension attempts to use them:
204 * ApiBase::getDescription() (deprecated in 1.25)
205 * ApiBase::getParamDescription() (deprecated in 1.25)
206 * ApiBase::getExamples() (deprecated in 1.25)
207 * ApiBase::getDescriptionMessage() (deprecated in 1.30)
208 Additionally, the 'APIGetDescription' and 'APIGetParamDescription' hooks have
209 been removed, as their only use was to let extensions override values returned
210 by getDescription() and getParamDescription(), respectively.
211 * API error codes may only contain ASCII letters, numbers, underscore, and
212 hyphen. Methods such as ApiBase::dieWithError() and
213 ApiMessageTrait::setApiCode() will throw an InvalidArgumentException if
214 passed a bad code.
215 * ApiBase::checkTitleUserPermissions() now takes an options array as its third
216 parameter. Passing a User object or null is deprecated.
217 * The api-feature-usage log channel now has log context. The text message is
218 deprecated and will be removed in the future.
219
220 === Languages updated in 1.33 ===
221 MediaWiki supports over 350 languages. Many localisations are updated regularly.
222 Below only new and removed languages are listed, as well as changes to languages
223 because of Phabricator reports.
224
225 * (T203908) Added language support for Eastern Pwo (kjp).
226 * (T213717) Fixed a translation error on Goan Konkani (gom-deva) translations
227 for NS_TEMPLATE.
228 * (T212221) Added $digitTransformTable for Santali (sat).
229 * (T216479) Added language support for Saisiyat (xsy).
230 * (T219728) Added support for new Japanese era name "Reiwa"
231
232 === Breaking changes in 1.33 ===
233 * The parameteter $lang in DifferenceEngine::setTextLanguage must be of type
234 Language. Other types are deprecated since 1.32.
235 * Skin::doEditSectionLink requires type Language for the parameter $lang.
236 The parameters $tooltip and $lang are mandatory. Omitting the parameters is
237 deprecated since 1.32.
238 * Language::truncate(), deprecated in 1.31, has been removed.
239 * UtfNormal, deprecated in 1.25, was removed. Use UtfNormal\Validator directly
240 instead.
241 * (T197179) In OOUI HTMLForm fields, the parameters 'notice', 'notice-messages',
242 and 'notice-message', which were deprecated in 1.32, were removed. Instead,
243 use 'help', 'help-message', and 'help-messages'.
244 * (T197179) HTMLFormField::getNotices(), deprecated in 1.32, was removed.
245 * The "Parsoid v1" compatibility mappings in ParsoidVirtualRESTService and
246 RestbaseVirtualRESTService, deprecated since 1.26, have been removed.
247 Use the RESTBase v1 or Parsoid v3 API instead.
248 * ParserOptions defaults 'tidy' to true now, since the untidy modes of the
249 parser are being deprecated and ParserOptions::getCanonicalOverrides()
250 has always been true at any rate.
251 * Support for disabling tidy and external tidy implementations has been removed.
252 This was deprecated in 1.32. The pure PHP Remex tidy implementation is now
253 used and no configuration is necessary.
254 * A number of deprecated methods for API documentation, intended for overriding
255 by extensions, are no longer called by MediaWiki, and will emit deprecation
256 notices if your extension attempts to use them:
257 * ApiBase::getDescription() (deprecated in 1.25)
258 * ApiBase::getParamDescription() (deprecated in 1.25)
259 * ApiBase::getExamples() (deprecated in 1.25)
260 * ApiBase::getDescriptionMessage() (deprecated in 1.30)
261 Additionally, the 'APIGetDescription' and 'APIGetParamDescription' hooks have
262 been removed, as their only use was to let extensions override values returned
263 by getDescription() and getParamDescription(), respectively.
264 * The authentication hooks 'AbortAutoAccount' 'AbortNewAccount', 'AbortLogin',
265 'LoginUserMigrated', 'UserCreateForm', and 'UserLoginForm', all deprecated by
266 the creation of AuthManager in 1.27, have been removed. This also means that
267 the FakeAuthTemplate and LoginForm classes are removed, that FakeAuthTemplate
268 is no longer passed into LoginSignupSpecialPage->getFieldDefinitions(), and
269 that LoginSignupSpecialPage->getBCFieldDefinitions() is removed.
270 * The 'jquery.localize' module, deprecated in 1.32, has been removed. Instead,
271 use 'jquery.i18n'.
272 * The hooks LanguageGetSpecialPageAliases and LanguageGetMagic, deprecated since
273 1.16, have now been removed. Instead, use $specialPageAliases or $magicWords
274 respectively in a $wgExtensionMessagesFiles file.
275 * The following methods of the Preferences class, deprecated in 1.31, have been
276 removed:
277 * getSaveBlacklist()
278 * loadPreferenceValues()
279 * getOptionFromUser()
280 * profilePreferences()
281 * skinPreferences()
282 * filesPreferences()
283 * datetimePreferences()
284 * renderingPreferences()
285 * editingPreferences()
286 * rcPreferences()
287 * watchlistPreferences()
288 * searchPreferences()
289 * miscPreferences()
290 * generateSkinOptions()
291 * getDateOptions()
292 * getImageSizes()
293 * getThumbSizes()
294 * validateSignature()
295 * cleanSignature()
296 * getTimezoneOptions()
297 * filterIntval()
298 * filterTimezoneInput()
299 * getTimeZoneList()
300 * mw.util.jsMessage(), deprecated in 1.20, was removed. Use mw.notify instead.
301 * (T61113) User::EDIT_TOKEN_SUFFIX was removed. It was deprecated since 1.27.
302 * The 'mediawiki.api' module aliases, deprecated in 1.32, have been removed.
303 Specifically: mediawiki.api.category, mediawiki.api.edit,
304 mediawiki.api.login, mediawiki.api.options, mediawiki.api.parse,
305 mediawiki.api.upload, mediawiki.api.user, mediawiki.api.watch,
306 mediawiki.api.messages, and mediawiki.api.rollback.
307 * The 'jquery.byteLimit' module alias for 'jquery.lengthLimit',
308 deprecated in 1.31, was removed.
309 * Revision::fetchRevision(), deprecated in 1.28, was removed.
310 * Class SquidUpdate, deprecated in 1.27, was removed.
311 * Title->getSquidURLs(), deprecated in 1.27, was removed. Instead, use
312 Title->getCdnUrls().
313 * Title::escapeFragmentForURL(), deprecated in 1.30, was removed. Use
314 Sanitizer::escapeIdForLink() or escapeIdForExternalInterwiki() instead.
315 * Title->canTalk(), deprecated in 1.30, was removed. Instead, use
316 Title->canHaveTalkPage().
317 * Title's methods for site and user page related to CSS and JS, deprecated in
318 1.31, were removed:
319 * Title->isCssOrJsPage() — Use Title->isSiteConfigPage()
320 * Title->isCssJsSubpage() – Use Title->isUserConfigPage()
321 * Title->getSkinFromCssJsSubpage() – Use Title->getSkinFromConfigSubpage()
322 * Title->isCssSubpage() – Use Title->isUserCssConfigPage()
323 * Title->isJsSubpage() – Use Title->isUserJsConfigPage()
324 * SiteSQLStore, deprecated in 1.27 and whose only method, ::newInstance(),
325 would return the global SiteStore instance, has been removed. You can get to
326 this via MediaWiki\MediaWikiServices::getInstance()->getSiteStore() directly.
327 * Linker::formatSize, deprecated in 1.28, has been removed (with DummyLinker's).
328 Instead, use Language->formatSize() with the relevant Language object.
329 * Linker::formatTemplates, deprecated in 1.28, has been removed (along with the
330 version in DummyLinker). You can use TemplatesOnThisPageFormatter directly.
331 * EventRelayerGroup::singleton(), deprecated in 1.27, has been removed. You can
332 use MediaWikiServices::getInstance()->getEventRelayerGroup() directly.
333 * LinkCache->addLink(), deprecated in 1.27, has been removed. It is thought to
334 be unused, and is distinct from OutputPage->addLink(), which remains.
335 * JsonContent->getJsonData(), deprecated in 1.25, has been removed. Instead, use
336 JsonContent->getData().
337 * MWExceptionHandler::getLogId(), deprecated in 1.27, has been removed, as the
338 exception ID is the same as the request ID, from WebRequest::getRequestId().
339 * SearchEngine::getNearMatchResultSet(), deprecated in 1.27, has been removed.
340 You can use SearchEngine::getNearMatcher() instead.
341 * EmailNotification::updateWatchlistTimestamp, deprecated in 1.27, has been
342 removed. Instead, use WatchedItemStore::updateNotificationTimestamp directly.
343 * User::getGroupName() and ::getGroupMember(), both deprecated in 1.29, have
344 been removed. Instead, please use UserGroupMembership::getGroupName() and
345 UserGroupMembership::getGroupMemberName().
346 * Backwards compatibility for setting wgSessionsInObjectCache to false or using
347 wgSessionHandler, both of which were deprecated in 1.27 with the introduction
348 of SessionManager, has been removed.
349 * SessionManager::autoCreateUser, deprecated in 1.27, has been removed. Use
350 MediaWiki\Auth\AuthManager::autoCreateUser instead.
351 * The mw.libs.jpegmeta property, deprecated in 1.31, was removed.
352 Use require( 'mediawiki.libs.jpegmeta' ) instead.
353 * The mw.user.stickyRandomId() method, deprecated in 1.32, was removed.
354 Use mw.user.getPageviewToken() instead.
355 * Removed deprecated class property WikiRevision::$importer.
356 * ResourceLoaderFileModule::readStyleFiles() now requires its $context
357 parameter.
358 * The ChangeList::insertArticleLink() method, that was deprecated in 1.27, has
359 been removed.
360 * MessageBlobStore::__construct() now requires its $rl parameter.
361 * Second parameter to Sanitizer::escapeIdReferenceList() (deprecated in 1.31)
362 has been removed.
363 * The 'jquery.xmldom' module has been removed.
364 * The 'jquery.mockjax' module has been removed.
365 * The 'jquery.hidpi' module, deprecated in 1.32, has been removed.
366 * AuthPlugin and related code, deprecated in 1.27, has been removed. Extensions
367 should instead use AuthManager. The following no longer exist:
368 * The AuthPlugin class itself and the related AuthPluginUser class and i18n
369 * The AuthPluginSetup and AuthPluginAutoCreate hooks
370 * The transitional wrapper classes AuthPluginPrimaryAuthenticationProvider,
371 AuthManagerAuthPlugin, and AuthManagerAuthPluginUser.
372 * The $wgAuth configuration setting and its use in Setup.php and unit tests
373 * (T217772) The 'wgAvailableSkins' mw.config key in JavaScript, was removed.
374 * Language::markNoConversion, deprecated in 1.32, has been removed. Use
375 LanguageConverter::markNoConversion instead.
376 * BagOStuff::modifySimpleRelayEvent() method has been removed.
377 * ParserOutput::getLegacyOptions, deprecated in 1.30, has been removed.
378 Use ParserOutput::allCacheVaryingOptions instead.
379 * CdnCacheUpdate::newSimplePurge, deprecated in 1.27, has been removed.
380 Use CdnCacheUpdate::newFromTitles() instead.
381 * Handling of multiple arguments by the Block constructor, deprecated in 1.26,
382 has been removed.
383 * The translation of main page in Sardinian (sc) was changed from "Pàgina Base"
384 to "Pàgina printzipale". Existing wikis using this content language need to
385 move the main page or change the name through MediaWiki:Mainpage page.
386 * wfSplitWikiID(), deprecated in 1.32, has been removed.
387 * MessageBlobStore::getBlob(), deprecated in 1.27, has been removed.
388 Use ::getBlobs() instead.
389 * The .background-size() LESS mixin, deprecated in 1.27, has been removed.
390 * ReadOnlyMode::clearCache() and ConfiguredReadOnlyMode::clearCache() have been
391 removed. Use MediaWikiTestCase::overrideMwServices() instead.
392 * Support for the 'aggregator' option of JobQueue (and thus $wgJobTypeConf) was
393 removed. The JobQueueAggregator interface and JobQueueAggregatorRedis class
394 have also been removed. They were experimentally developed for use by the
395 Wikimedia Foundation, but were never used, with no known use cases. (Note that
396 this does not affect JobQueueRedis which is still supported.)
397
398 === Deprecations in 1.33 ===
399 * The configuration option $wgUseESI has been deprecated, and is expected
400 to be removed in a future release.
401 * The configuration option $wgSquidPurgeUseHostHeader has been deprecated,
402 and is expected to be removed in a future release.
403 * The configuration options $wgFixArabicUnicode and $wgFixMalayalamUnicode,
404 introduced in MW 1.17, have been deprecated. These fixes will always be
405 applied for Arabic and Malayalam in the future. Please enable these on
406 your local wiki (if you have them explicitly set to false) and run
407 maintenance/cleanupTitles.php to fix any existing page titles.
408 * The LegacyHookPreAuthenticationProvider class, deprecated since its creation
409 in 1.27 as part of the AuthManager re-write, now emits deprecation warnings.
410 This will help identify the issue if you added it to $wgAuthManagerConfig.
411 * wfSplitWikiId() is now deprecated. Cache key generation should have the wiki
412 domain ID as a key component and use makeGlobalKey().
413 * (T202094) Title::getUserCaseDBKey() is deprecated; instead, please use
414 Title::getDBKey(), which doesn't vary case.
415 * User::getPasswordValidity() is now deprecated. User::checkPasswordValidity()
416 returns the same information in a more useful format.
417 * For Linker::generateTOC() and Linker::tocList(), passing strings or booleans
418 as the $lang parameter was deprecated. The same applies to DummyLinker.
419 * The PasswordPolicy 'PasswordCannotBePopular' has been deprecated. To
420 follow best practices, it is reccommended to use 'PasswordNotInLargeBlacklist'
421 instead which blacklists 100,000 commonly used passwords.
422 * (T208862) Action::requiresUnblock() is now called from
423 Title::getUserPermissionsErrors() and Title::userCan(). Previously, the method
424 was only called in Action::checkCanExecute(). Actions should ensure that their
425 requiresUnblock() returns the proper result (the default is `true`).
426 * (T211608) The MediaWiki\Services namespace has been renamed to
427 Wikimedia\Services. The old name is still supported, but deprecated.
428 * (T155582) Content::getNativeData has been deprecated. Please use model-
429 specific getters, such as TextContent::getText().
430 * The class WebInstallerOutput is now marked as @private.
431 * (T209699) The jquery.async module has been deprecated. JavaScript code that
432 needs asynchronous behaviour should use Promises.
433 * Password::equals() is deprecated, use verify().
434 * BaseTemplate::msgWiki() and QuickTemplate::msgWiki() will be removed. Use
435 other means to fetch a properly escaped message string or Message object.
436 * (T126091) The 'ResourceLoaderTestModules' hook, which lets you declare QUnit
437 testing code for your JavaScript modules, is deprecated. Instead, you can now
438 use the new extension registration key 'QUnitTestModule'.
439 * (T213426) The jquery.throttle-debounce module has been deprecated. JavaScript
440 code that needs this behaviour should use OO.ui.debounce/throttle.
441 * The mw.language.specialCharacters property from the
442 'mediawiki.language.specialCharacters' module has been deprecated.
443 Use require( 'mediawiki.language.specialCharacters' ) instead.
444 * ChangeTags::purgeTagUsageCache() has been deprecated, and is expected to be
445 removed in a future release.
446 * Passing a User object or null as the third parameter to
447 ApiBase::checkTitleUserPermissions() has been deprecated. Pass an array
448 [ 'user' => $user ] instead.
449 * (T211578) Block::prevents is deprecated. Use Block::isEmailBlocked,
450 Block::isCreateAccountBlocked and Block::isUsertalkEditAllowed to get and set
451 block properties; use Block::appliesToRight and Block::appliesToUsertalk to
452 check block behaviour.
453 * The api-feature-usage log channel now has log context. The text message is
454 deprecated and will be removed in the future.
455 * The FileBasedSiteLookup class has been deprecated. For a cacheable SiteLookup
456 implementation, use CachingSiteStore instead.
457 * Language::viewPrevNext function is deprecated, use
458 SpecialPage::buildPrevNextNavigation instead
459 * ManualLogEntry::setTags() is deprecated, use ManualLogEntry::addTags()
460 instead. The setTags() method was overriding the tags, addTags() doesn't
461 override, only adds new tags.
462 * Block::isValid is deprecated, since it is no longer needed in core.
463 * Calling Maintenance::hasArg() as well as Maintenance::getArg() with no
464 parameter has been deprecated. Please pass the argument number 0.
465 * ResourceLoaderContext::expandModuleNames has been deprecated.
466 Use ResourceLoader::expandModuleNames instead.
467
468 === Other changes in 1.33 ===
469 * (T201747) Html::openElement() warns if given an element name with a space
470 in it.
471 * The implementation of buildStringCast() in Wikimedia\Rdbms\Database has
472 changed to explicitly cast. Subclasses relying on the base-class
473 implementation should check whether they need to override it now.
474 * BagOStuff::add is now abstract and must explicitly be defined in subclasses.
475 * LinksDeletionUpdate is now a subclass of LinksUpdate. As a consequence,
476 the following hooks will now be triggered upon page deletion in addition
477 to page updates: LinksUpdateConstructed, LinksUpdate, LinksUpdateComplete.
478 LinksUpdateAfterInsert is not triggered since deletions do not cause
479 insertions into links tables.
480 * Category::newFromID( $id )->getID() will now return $id without any
481 validation, to avoid a mostly unnecessary DB query.
482 * On Special:Version, the name for an extension can no longer be arbitrary
483 html when no link is specified.
484
485
486 = MediaWiki 1.32 =
487
488 == MediaWiki 1.32.3 ==
489
490 This is a maintenance release of the MediaWiki 1.32 branch.
491
492 === Changes since MediaWiki 1.32.2 ===
493 * (T225558) Update installer link to PHP intl.
494 * (T225496) Detect APC for MainCacheType in CLI installer.
495 * (T226766) Remove jetbrains/phpstorm-stubs from composer dev dependancies.
496 * (T202211) Fix SQLite patch-(image|page|template)links-fix-pk.sql column order.
497
498 == MediaWiki 1.32.2 ==
499
500 This is a security and maintenance release of the MediaWiki 1.32 branch.
501
502 === Changes since MediaWiki 1.32.1 ===
503 * (T204423) Backport support for hyphenated DB names in JobQueueGroup.
504 * (T216968) Return pageid as int in both list=iwbacklinks and
505 list=langbacklinks.
506 * (T215169) Fix for Database::update() with IGNORE option fails on PostgreSQL.
507 * (T199474) Fix typo in rebuildrecentchanges.php resulting in rogue flags.
508 * (T218608) SECURITY: Fix an issue that prevents Extension:OAuth working when
509 $wgBlockDisablesLogin is true.
510 * (T216029) Chrome redirects to Special:BadTitle after editing a section with
511 a non-Latin name on a page with non-Latin characters in title.
512 * Unbreak language related maintenance scripts that use StaticArrayWriter.
513 * (T219728) Added support for new Japanese era name "Reiwa".
514 * (T25227) SECURITY: action=logout now requires to be posted and have a csrf
515 token.
516 * Updated cssjanus/cssjanus from 1.2.0 to 1.3.0.
517 * (T221045) Remove orphaned code from ConfigRepository.
518 * (T222385) resourceloader: Use AND instead of OR for upsert conds in
519 saveFileDependencies().
520 * (T224374) Fix message parameters so that the message that says SQLite is
521 out of date makes sense.
522 * (T200471) Prevent LBFactorySimple breaking ExternalStorage, when trying to
523 connect to external server with local database name.
524 * (T197279) SECURITY: Fix reauth in Special:ChangeEmail.
525 * (T208881) SECURITY: blacklist CSS var().
526 * (T209794) SECURITY: rate-limit and prevent blocked users from changing email.
527 * (T199540) SECURITY: API: Respect $wgBlockCIDRLimit in action=block.
528 * (T212118) SECURITY: Fix cache mode for (un)patrolled recent changes query.
529 * (T222036, T222038) SECURITY: Add permission check for user is permitted to
530 view the log type.
531 * (T221739) SECURITY: resources: Patch jQuery 3.3.1 for CVE-2019-11358.
532
533 == MediaWiki 1.32.1 ==
534
535 === Changes since MediaWiki 1.32.0 ===
536 * (T213577) rdbms: avoid transaction status errors from ping() in rollback().
537 * rdbms: Pass required parameter.
538 * rdbms: do not treat SAVEPOINT and RELEASE SAVEPOINT as write queries.
539 * (T204531) rdbms: reduce LoadBalancer replication log spam.
540 * (T213489) Avoid session double-start in Setup.php.
541 * (T213717) Correct namespace 'Template' for gom-deva
542 * (T198054) Fix login page crash caused by unknown language via ?uselang
543 * (T215324) (T210937) list=users mistakenly reports user as missing.
544 * (T209483) Add ILBFactory::redefineLocalDomain method. This is intended for
545 use with scripts like addWiki.php to avoid mismatched domain errors.
546 * (T208871) The hard-coded Google search form on the database error page was
547 removed.
548 * (T204800) Fix Title::getFragmentForURL for bad interwiki prefix
549 * (T215566) Fix installer being unable to determine if the database exists
550 during a fresh installation.
551
552 == MediaWiki 1.32.0 ==
553
554 === Changes since MediaWiki 1.32.0-rc.2 ===
555 * (T188327) Fix slow queries in migrateActors.php.
556 * (T102320) Fix $magicWords for the Sanskrit language.
557
558 === Changes since MediaWiki 1.32.0-rc.1 ===
559 * Fix addition of ug_expiry column to user_groups table on MSSQL.
560 * (T210307) Fix the cache timestamp for forced updates.
561 * (T210621) User: Bypass repeatable-read when creating an actor_id.
562 * (T197535) Extensions can now specify PHP versions and PHP extensions they
563 depend on.
564 * Updated wikimedia/ip-set from v1.2.0 to v1.3.0.
565 * (T212356) When using action=delete on pages with many revisions, the module
566 may return a boolean-true 'scheduled' and no 'logid'. This signifies that the
567 deletion will be processed via the job queue.
568 * (T64103) Dropped columns category.cat_hidden, site_stats.ss_admins, and
569 recentchanges.rc_cur_time from the PostgreSQL schema.
570
571 === Changes since MediaWiki 1.32.0-rc.0 ===
572 * (T209885) Prevent populateSearchIndex.php from breaking once actor migration
573 has been started.
574 * (T210998) Properly set $wgLanguageCode in the generated LocalSettings.php
575 if --lang is used with the command-line installer (install.php).
576
577 === Configuration changes in 1.32 ===
578
579 ==== New configuration ====
580 * $wgJpegQuality – The quality of JPEG thumbnails is now configurable through
581 this setting. The default is 80, which matches the quality of JPEG thumbnails
582 previously generated by ImageMagick. The quality of JPEG thumbnails generated
583 by GD was previously 95, but now uses the $wgJpegQuality setting as well.
584 * $wgCookieSetOnIpBlock - This determines whether to set a cookie when an IP
585 user is blocked. Doing so means that a blocked user, even after moving to a
586 new IP address, will still be blocked.
587 * $wgRawHtmlMessages – This new configuration setting is added for listing
588 messages which are displayed as raw HTML.
589 * $wgCSPHeader and $wgCSPReportOnlyHeader – You can now define a
590 "Content Security Policy" for your wiki. This adds a defense-in-depth feature
591 to stop an attacker who has found a bug in the parser allowing them to insert
592 malicious attributes. Disabled by default. (T135963)
593 * $wgGroupPermissions – A new user group, 'interface-admin', is added for
594 controlling access to sitewide CSS/JS (and editing other users' CSS/JS). No
595 other group has 'editsitecss', 'editusercss', 'editsitejs' or 'edituserjs'
596 by default.
597 * $wgGrantPermissions – A new grant group, 'editsiteconfig', is added for
598 granting the above rights.
599 * $wgDBDefaultGroup – A default database group for use by maintenance scripts.
600 * $wgResourceLoaderEnableJSProfiler – This new configuration setting lets you
601 enable client-side profiling of JavaScript modules; it is off by default.
602 * (T193868) $wgChangeTagsSchemaMigrationStage — This temporary configuration
603 setting allows sysadmins to gradually migrate the database table schema for
604 how change tags are stored.
605 * (T199334) $wgTagStatisticsNewTable — This temporary configuration setting
606 allows sysadmins to enable the caching of Special:Tags via the new
607 change_tag_def table.
608
609 ==== Changed configuration ====
610 * $wgUseAjax – This setting, deprecated in 1.31, is now ignored.
611 * $wgDefaultUserOptions – The default watchlist view time (watchlistdays) has
612 been increased from 3 to 7 days. (T194414)
613 * $wgGroupPermissions – The right to edit sitewide Javascript
614 (e.g. MediaWiki:Common.js), CSS or JSON was separated from 'editinterface'
615 and is available under 'editsitejs'/'editsitecss'/'editsitejson'. Having
616 'editinterface' is still necessary to edit such pages.
617 * $wgMultiContentRevisionSchemaMigrationStage now defaults to writing both the
618 old and the new schema, but reading the new schema, so Multi-Content Revisions
619 (MCR) are now functional per default. The new default value of the setting is
620 SCHEMA_COMPAT_WRITE_BOTH | SCHEMA_COMPAT_READ_NEW.
621 * $wgActorTableSchemaMigrationStage no longer accepts MIGRATION_WRITE_BOTH or
622 MIGRATION_WRITE_NEW. It instead uses SCHEMA_COMPAT_WRITE_BOTH |
623 SCHEMA_COMPAT_READ_OLD and SCHEMA_COMPAT_WRITE_BOTH | SCHEMA_COMPAT_READ_NEW
624 for intermediate stages of migration.
625 * $wgDBTableOptions – The default table options now use the binary charset. The
626 default was already overridden in the installer-generated LocalSettings.php,
627 and so is always set to binary after the installer UI option was removed. The
628 default value is only used when the installer installs an extension.
629 * $wgPopularPasswordFile — The location of the default popular passwords file
630 has been moved to be in line with other non-PHP files used by libraries and
631 classes.
632 * $wgEnableImageWhitelist is now disabled by default, as it opens up a hole for
633 potential privacy leaks by administrators. You can check
634 "MediaWiki:External image whitelist" on your wiki to see whether the feature
635 was ever used, and whether it needs to be re-enabled.
636
637 ==== Removed configuration ====
638 * $wgEnableAPI and $wgEnableWriteAPI – These settings, deprecated in 1.31,
639 have been removed. (T115414)
640 * $wgSiteSupportPage – This setting, unused since 1.5, was removed.
641 * $wgBrowserBlacklist – This setting, deprecated in 1.30, was removed.
642 * $wgExperimentalHtmlIds – This setting, deprecated since 1.30, was removed.
643 The 'html5-legacy' value for $wgFragmentMode is no longer accepted.
644 * $wgPasswordSenderName - This setting, ignored since 1.23 by MediaWiki and
645 most extensions, is no longer set. Instead, you can modify the system
646 message `emailsender`.
647 * $wgTidyConfig – The experimental Html5Internal and Html5Depurate tidy drivers
648 were removed. RemexHtml, which is the default, should be used instead.
649 * (T181318) The $wgStyleVersion setting and its appendage to various script and
650 style URLs in OutputPage, deprecated in 1.31, was removed.
651 * (T140807) The wgResourceLoaderLESSImportPaths configuration option was removed
652 from ResourceLoader. Instead, use `@import` statements in LESS to import
653 files directly from nearby directories within the same project.
654 * (T140804) The wgResourceLoaderLESSVars configuration option, deprecated
655 since 1.30, was removed. Instead, to expose variables from PHP to LESS, use
656 the ResourceLoaderModule::getLessVars() method.
657 * $wgResourceLoaderValidateStaticJS – This setting, unused since MediaWiki 1.18,
658 was removed.
659 * Two temporary variables for deploying the feature of filters on change lists,
660 $wgStructuredChangeFiltersShowPreference introduced in MediaWiki 1.30 and
661 $wgStructuredChangeFiltersOnWatchlist in 1.31, were removed.
662
663 === New features in 1.32 ===
664 * (T112474) Generalized the ResourceLoader mechanism for overriding modules
665 using a particular page during edit previews.
666 * (T12331) You can now log page creation events by setting $wgPageCreationLog
667 to true.
668 * Added 'ApiParseMakeOutputPage' hook.
669 * (T174313) Added checkbox on Special:ListUsers to display only users in
670 temporary user groups.
671 * (T152462) A cookie can now be set when an IP user is blocked to track that
672 user if they move to a new IP address. This is disabled by default.
673 * (T194950) Added 'ApiMaxLagInfo' hook.
674 * SpecialPage::checkLoginSecurityLevel() will now preserve POST data when
675 reauthenticating.
676 * FormSpecialPage::execute() will now call checkLoginSecurityLevel() if
677 getLoginSecurityLevel() returns non-false.
678 * The 'ImageBeforeProduceHTML' hook is now passed three new parameters, $parser,
679 &$query and &$widthOption, allowing extensions even finer control over the
680 resulting HTML code.
681 * Added new 'ArticleShowPatrolFooter' hook, which allows extensions to determine
682 if the [mark as patrolled] link should be shown at the footer of patrollable
683 pages.
684 * The array of hidden options ($opts) passed to the 'SpecialSearchPowerBox' hook
685 is now passed by reference, allowing extensions to modify or even unset it.
686 * Added new 'OutputPageAfterGetHeadLinksArray' hook, allowing extensions to
687 modify the return value of OutputPage#getHeadLinksArray in order to add,
688 remove or otherwise alter the elements to be output in the page <head>.
689 * (T28934) The 'HistoryPageToolLinks' hook allows extensions to append
690 additional links to the subtitle of a history page.
691 * The 'GetLinkColours' hook now receives an additional $title parameter,
692 the Title object of the page being parsed, on which the links will be shown.
693 * (T194731) DifferenceEngine supports multiple slots. Added SlotDiffRenderer to
694 render diffs between two Content objects, and DifferenceEngine::setRevisions()
695 to render diffs between two custom (potentially multi-content) revisions.
696 Added GetSlotDiffRenderer hook which works like GetDifferenceEngine for slots.
697 * Added a temporary action=mcrundo to the web UI, as the normal undo logic
698 can't yet handle MCR and deadlines are forcing is to put off fixing that.
699 This action should be considered deprecated and should not be used directly.
700 * Extensions overriding ContentHandler::getUndoContent() will need to be
701 updated for the changed method signature.
702 * Added a new hook, 'UserGetRightsRemove', which can be used to remove rights
703 from user. Unlike the 'UserGetRights' it will ensure that removed rights
704 will not be reinserted.
705 * (T197535) Extensions can now specify PHP versions and PHP extensions they
706 depend on.
707
708 === External library changes in 1.32 ===
709
710 ==== New external libraries ====
711 * Added pear/Net_SMTP v1.8.0.
712 * Added wikimedia/xmp-reader v0.6.0.
713
714 * Added cache/integration-tests v0.16.0 (dev-only).
715 * Added giorgiosironi/eris v0.10.0 (dev-only).
716 * Added seld/jsonlint v1.7.1 (dev-only).
717
718 * Added EasyDeflate (unversioned).
719
720 ==== Changed external libraries ====
721 * Updated OOUI from v0.26.3 to v0.29.2.
722 * Updated wikimedia/base-convert from v1.0.1 to v2.0.0.
723 * Updated wikimedia/remex-html from v1.0.3 to v2.0.1.
724 * Updated wikimedia/scoped-callback from v1.0.0 to v2.0.0.
725 ** ScopedCallback objects can no longer be serialized.
726 * Updated wikimedia/timestamp from v1.0.0 to v2.2.0.
727 * Updated wikimedia/wrappedstring from v2.3.0 to v3.0.1.
728 * oyejorge/less.php replaced with our fork wikimedia/less.php
729 * Updated wikimedia/ip-set from v1.2.0 to v1.3.0.
730
731 * Updated composer/spdx-licenses from v1.3.0 to v1.4.0 (dev-only).
732 * Updated mediawiki/mediawiki-codesniffer from v18.0.0 to v22.0.0 (dev-only).
733 * Updated psy/psysh from v0.8.11 to v0.9.6 (dev-only).
734
735 * Updated CLDRPluralRuleParser from v0.1.0 to v1.3.2-pre.
736 * Updated jquery from v3.2.1 to v3.3.1.
737 * Updated jquery.client from v2.0.0 to v2.0.1.
738 * Updated jquery.i18n from v1.0.4 to v1.0.5.
739 * Updated mustache.js from v0.8.2-d9aa703 to v1.0.0.
740 * Updated OOjs from v2.2.0 to v2.2.2.
741 * Updated qunitjs from v2.4.0 to v2.6.2.
742 * Updated sinonjs from v1.17.3 to v1.17.7.
743
744 ==== Removed external libraries ====
745 * pear/mail_mime-decode was removed.
746
747 === Bug fixes in 1.32 ===
748 * SpecialPage::execute() will now only call checkLoginSecurityLevel() if
749 getLoginSecurityLevel() returns non-false.
750 * (T43720, T46197) Improved page display title handling for category pages
751 * (T65080) Fixed resetting options of some types via API action=options.
752
753 === Action API changes in 1.32 ===
754 * Added templated parameters.
755 * A module can define a templated parameter like "{fruit}-quantity", where
756 the actual parameters recognized correspond to the values of a multi-valued
757 parameter. Then clients can make requests like
758 "fruits=apples|bananas&apples-quantity=1&bananas-quantity=5".
759 * action=paraminfo will return templated parameter definitions separately
760 from normal parameters. All parameter definitions now include an "index"
761 key to allow clients to maintain parameter ordering when merging normal and
762 templated parameters.
763 * It is now an error to submit too many values for a multi-valued parameter.
764 This has generated a warning since MediaWiki 1.14.
765 * Assertion failures from the 'assert' and 'assertuser' parameters will no
766 longer use the action module's custom response format, for the few modules
767 that use custom formatters that handle errors.
768 * (T198935) User list preferences such as `email-blacklist` and similar
769 extension preferences are no longer represented as arrays when returned by
770 action=query&meta=userinfo&uiprop=options.
771 * 'missingparam' errors will now use the prefixed parameter name in the code
772 and error text, e.g. "noxxfoo" and "The 'xxfoo' parameter must be set" rather
773 than "nofoo" and "The 'foo' parameter must be set".
774 * action=query&prop=revisions now takes a 'rvslots' parameter to indicate the
775 multi-content revision slots for which content should be returned. It also
776 has a new rvprop, 'roles', to indicate which roles have slots. A deprecation
777 warning will be issued if rvprop=content or rvprop=contentmodel are used
778 without rvslots.
779 * The rvcontentformat parameter to action=query&prop=revisions has been
780 deprecated. Clients should be prepared to deal with the default format for
781 relevant models.
782 * Use of the deprecated parameters rvexpandtemplates, rvgeneratexml, rvparse,
783 rvdiffto, rvdifftotext, rvdifftotextpst, rvcontentformat, or the deprecated
784 rvprop=parsetree is forbidden with the new 'rvslots' parameter.
785 * action=query&prop=deletedrevisions, action=query&list=allrevisions, and
786 action=query&list=alldeletedrevisions are changed similarly to
787 &prop=revisions (see the three previous items).
788 * (T174032) action=compare now supports multi-content revisions.
789 * It has a 'slots' parameter to select diffing of individual slots. The
790 default behavior is to return one combined diff.
791 * The 'fromtext', 'fromsection', 'fromcontentmodel', 'fromcontentformat',
792 'totext', 'tosection', 'tocontentmodel', and 'tocontentformat' parameters
793 are deprecated. Specify the new 'fromslots' and 'toslots' to identify which
794 slots have text supplied and the corresponding templated parameters for
795 each slot.
796 * The behavior of 'fromsection' and 'tosection' of extracting one section's
797 content is not being preserved. 'fromsection-{slot}' and 'tosection-{slot}'
798 instead expand the given text as if for a section edit. This effectively
799 declines T183823 in favor of T185723.
800 * (T198214) The 'disabletidy' parameter to action=parse has been
801 deprecated; untidy output will not be supported by future wikitext
802 parsers.
803 * Added intestactionsdetail to action=query&prop=info to allow retrieving the
804 reasons an action is not allowed.
805 * Deprecated action=query&prop=info inprop=readable in favor of
806 intestactions=read.
807 * (T212356) When using action=delete on pages with many revisions, the module
808 may return a boolean-true 'scheduled' and no 'logid'. This signifies that the
809 deletion will be processed via the job queue.
810
811 === Action API internal changes in 1.32 ===
812 * Added 'ApiParseMakeOutputPage' hook.
813 * Parameter names may no longer contain '{' or '}', as these are now used for
814 templated parameters.
815 * (T194950) Added 'ApiMaxLagInfo' hook.
816 * The following methods now take a RevisionRecord rather than a Revision. No
817 external callers are known.
818 * ApiFeedContributions::feedItemAuthor()
819 * ApiFeedContributions::feedItemDesc()
820 * ApiQueryRevisionsBase::extractRevisionInfo()
821 * The following deprecated methods have been removed:
822 * ApiBase::profileIn() (deprecated in 1.25)
823 * ApiBase::profileOut() (deprecated in 1.25)
824 * ApiBase::safeProfileOut() (deprecated in 1.25)
825 * ApiBase::profileDBIn() (deprecated in 1.25)
826 * ApiBase::profileDBOut() (deprecated in 1.25)
827 * ApiBase::dieUsage() (deprecated in 1.29)
828 * ApiBase::dieUsageMsg() (deprecated in 1.29)
829 * ApiBase::dieUsageMsgOrDebug() (deprecated in 1.29)
830 * ApiBase::getErrorFromStatus() (deprecated in 1.29)
831 * ApiBase::parseMsg() (deprecated in 1.29)
832 * ApiBase::setWarning() (deprecated in 1.29)
833 * ApiPageSet::getInvalidTitles() (deprecated in 1.26)
834 * ApiQueryLogEvents::addLogParams() (deprecated in 1.25)
835 * ApiUsageException::getCodeString() (deprecated in 1.29)
836 * ApiUsageException::getMessageArray() (deprecated in 1.29)
837 * Class UsageException, deprecated in 1.29, has been removed.
838 * ApiErrorFormatter: Added getFormat() and newWithFormat(). In particular, you
839 can now easily test $formatter->getFormat() === 'bc', and then call
840 $formatter->newWithFormat( 'plaintext' ) to get a non-BC formatter.
841
842 === Languages updated in 1.32 ===
843 MediaWiki supports over 350 languages. Many localisations are updated regularly.
844 Below only new and removed languages are listed, as well as changes to languages
845 because of Phabricator reports.
846
847 * (T193566) Added language support for Ambonese Malay (abs).
848 * (T194047) Added language support for Shawiya, Latin script (shy-latn).
849 * (T195940) Added language support for Batak Mandailing (btm).
850 * (T137491) Added language support for Standard Moroccan Amazigh (zgh).
851 * (T198132) Added language support for Manipuri (mni).
852 * (T201276) Added language support for Western Armenian (hyw).
853 * (T201583) Added language support for Mon (mnw).
854
855 === Breaking changes in 1.32 ===
856 * $wgRequestTime, deprecated in 1.25, was removed. Use
857 $_SERVER['REQUEST_TIME_FLOAT'] or WebRequest::getElapsedTime() instead.
858 * The MediaWikiI18N class, deprecated in 1.31, was removed.
859 * QuickTemplate::setTranslator(), deprecated in 1.31, was removed. Use
860 Skin::msg() instead.
861 * wfInitShellLocale(), deprecated in 1.30, was removed.
862 * wfShellExecDisabled(), deprecated in 1.30, was removed.
863 * The type string for the parameter $lang of DateFormatter::getInstance,
864 deprecated in 1.31, was removed.
865 * The EDIT_TOKEN_SUFFIX constant deprecated in 1.27, was removed. Use
866 MediaWiki\Session\Token::SUFFIX instead.
867 * EditPage::isOouiEnabled() deprecated in 1.30, was removed.
868 * mw.util.wikiGetlink(), deprecated in 1.23, was removed. Use mw.util.getUrl()
869 instead.
870 * (T61113) The following methods and constants from the Revision class, which
871 were deprecated in 1.25, have now been removed:
872 * Revision::getRawUser()
873 * Revision::getRawUserText()
874 * Revision::getRawComment()
875 * window.gM() from mediawiki.jqueryMsg, deprecated in 1.23, was removed. Use
876 mw.msg() or mw.message() instead.
877 * mw.util.escapeId(), deprecated in 1.30, was removed. Use
878 mw.util.escapeIdForAttribute or mw.util.escapeIdForLink instead.
879 * mw.util.updateTooltipAccessKeys(), deprecated in 1.24, was removed. Use
880 jquery.accessKeyLabel instead.
881 * The SqlDataUpdate class, deprecated in 1.28, has been removed.
882 * The Html5Internal and Html5Depurate tidy driver classes were removed, along
883 with the Balancer tidy implementation. Both implementations were experimental,
884 and were replaced by RemexHtml.
885 * (T179624) Job::insert() and ::batchInsert(), deprecated in 1.21, were both
886 removed. Use JobQueueGroup::singleton()->push() instead.
887 * The jquery.footHovzer module, for mediawiki.debug, was removed.
888 * The es5-shim module, empty and deprecated since 1.29, was removed.
889 * the dom-level2-shim module, empty and deprecated since 1.29, was removed.
890 * the json module, empty and deprecated since 1.29, was removed.
891 * The mediawiki.widgets.visibleByteLimit module alias, deprecated in 1.32, was
892 removed. Use mediawiki.widgets.visibleLengthLimit instead.
893 * The jquery.farbtastic module, unused since 1.18, was removed.
894 * The 'jquery.expandableField' module, unused since 1.22, was removed.
895 * The hooks 'PreferencesFormPreSave' and 'PreferencesGetLegend' may provide
896 any HTMLForm object rather than PreferencesForm.
897 * The non namespaced TimestampException class, deprecated in 1.29, was removed.
898 Use Wikimedia\Timestamp\TimestampException instead.
899 * The global functions codepointToUtf8, hexSequenceToUtf8, utf8ToHexSequence,
900 utf8ToCodepoint, and escapeSingleString (deprecated in 1.25) were removed.
901 The UtfNormal\Utils class from the utfnormal library should be used instead.
902 * The deprecated UTF8_ and UNICODE_ constants were removed. The class constants
903 from the UtfNormal\Constants class from the utfnormal library should be used
904 * The protected methods PHPSessionHandler::returnSuccess() and returnFailure(),
905 only needed for PHP5 compatibility, have been removed. It now uses the boolean
906 values `true` and `false` respectively.
907 * The $parserMemc global and wfGetParserCacheStorage(), deprecated since 1.30,
908 were removed. Use the ParserCache class instead.
909 * ScopedCallback (deprecated in 1.28) was removed. Use Wikimedia\ScopedCallback
910 instead.
911 * Support for ResourceLoaderModule::getModifiedTime() and getModifiedHash(),
912 deprecated since 1.26, was removed. Use getDefinitionSummary() instead.
913 * (T195256) Skins are recommended not to rely on JavaScript for the "mw-jump"
914 and "jump-to-nav" accessibility links. To this end, the "jquery.mw-jump"
915 is no longer loaded by default. The Vector and MonoBook skins have made a
916 minor change to implement the toggle feature with CSS instead. To restore
917 prior functionality, either explicitly load "jquery.mw-jump" in your skin
918 or refer to T195256 for details on how to make the same change.
919 * Hook 'EditPageBeforeEditChecks' was removed;
920 use 'EditPageGetCheckboxesDefinition' instead.
921 * Linker::getLinkColour() and DummyLinker::getLinkColour(), deprecated since
922 1.28, were removed. LinkRenderer::getLinkClasses() should be used instead.
923 * Wikimedia\Rdbms\LoadBalancer::getLaggedSlaveMode(), deprecated in 1.28, has
924 been removed. Use Wikimedia\Rdbms\LoadBalancer::getLaggedReplicaMode()
925 instead.
926 * mw.widgets.CategoryMultiselectWidget now uses TagMultiselectWidget instead of
927 CapsuleMultiselectWidget. The following methods may no longer be used:
928 * setItemsFromData: Use setValue instead
929 * getItemsData: Use getItems instead and get the data property
930 * Two OutputPage methods, addMetadataLink() and getMetadataAttribute(), were
931 removed. Use addLink() instead.
932 * Another two OutputPage methods, setPageTitleActionText() and
933 getPageTitleActionText(), were removed. They did nothing since 1.15 (almost
934 ten years). Use setHTMLTitle() directly.
935 * The return value of OutputPage::adaptCdnTTL() has been removed. The
936 value returned was misleading and probably not what any caller would
937 have wanted.
938 * All MagicWord static member variables have been removed. Use appropriate
939 hooks or MagicWordFactory methods instead.
940 * MagicWord::clearCache() has been removed. Instead, create a new
941 MagicWordFactory, such as by calling
942 resetServiceForTesting( 'MagicWordFactory' ) on a MediaWikiServices.
943 * mw.util.init() has been removed. This function is not needed anymore and was
944 a no-op function since 1.30.
945 * SpecialPageFactory::resetList() is a no-op. Call overrideMwServices()
946 instead.
947 * MediaWiki no longer supports a StartProfiler.php file. Instead, you can set
948 $wgProfiler and $wgEnableProfileInfo.
949 * The mw.loader.addSource() is now considered a private method, and no longer
950 supports the `id, url` signature. Use the `Object` parameter instead.
951 * The backwards-compatibility code in HTMLForm to add a drop-down control to an
952 option that is not set to be a drop-down if the "mw-chosen" class is present,
953 is now removed.
954 * Several collations were removed. They were workarounds for bugs in the ICU
955 library and they are no longer needed (as of ICU 57.1):
956 * 'uppercase-se' (NorthernSamiUppercaseCollation) - use 'uca-se' instead
957 * 'xx-uca-et' (CollationEt) - use 'uca-et' instead
958 * 'xx-uca-fa' (CollationFa) - use 'uca-fa' instead
959 * LanguageCode::bcp47() now always returns a valid BCP 47 code. This means
960 that some MediaWiki-specific language codes, such as `simple`, are mapped
961 into valid BCP 47 codes (eg `en-simple`).
962 * The hooks 'SpecialRecentChangesFilters' & 'SpecialWatchlistFilters' deprecated
963 in 1.23 were removed. Instead, use 'ChangesListSpecialPageStructuredFilters'.
964 The ChangesListSpecialPage code for these legacy hooks, and their use in
965 SpecialRecentchanges.php and SpecialWatchlist, was also removed:
966 * ChangesListSpecialPage->getCustomFilters()
967 * ChangesListSpecialPage->getFilterGroupDefinitionFromLegacyCustomFilters()
968 * ChangesListSpecialPage::customFilters
969 * The global function wfUseMW, deprecated since 1.26, has now been removed. Use
970 the "requires" property of static extension registration instead.
971 * $wgSpecialPages no longer accepts array syntax, deprecated since 1.18.
972 * The MailAddress constructor can no longer be called with a User object,
973 behaviour which has been deprecated since 1.24.
974 * LBFactory, deprecated since 1.28, has been removed. Instead, use
975 Wikimedia\Rdbms\LBFactory.
976 * The MimeMagic class, deprecated since 1.28 has been removed. Get a
977 MimeAnalyzer instance from MediaWikiServices instead.
978 * The '--tidy' option to maintenance/parse.php has been removed. Tidying
979 the output is now the default. Use '--no-tidy' to bypass the tidy
980 phase.
981 * The global function wfErrorLog, deprecated since 1.25, has now been removed.
982 Use MWLoggerLegacyLogger::emit or UDPTransport.
983 * The hooks 'SpecialRecentChangesQuery' & 'SpecialWatchlistQuery', deprecated in
984 1.23, were removed. Instead, use ChangesListSpecialPageStructuredFilters or
985 ChangesListSpecialPageQuery.
986 * The global function wfUsePHP, deprecated since 1.30, has now been removed. To
987 assert a newer version of PHP than MediaWiki does, use extension registration.
988 * The hook 'ChangesListSpecialPageFilters', deprecated in 1.29, has now been
989 removed. Use the 'ChangesListSpecialPageStructuredFilters' hook instead.
990 * DeferredUpdates::setImmediateMode(), deprecated since 1.29, has been removed.
991 * File / MediaHandler::getStreamHeaders(), deprecated since 1.30, was removed.
992 * The hook 'DoEditSectionLink', deprecated since 1.25, has been removed. Use
993 the hook 'SkinEditSectionLinks' instead.
994 * The hook 'UserGetImplicitGroups', deprecated since 1.25, has been removed.
995 * The global function wfRunHooks, deprecated since 1.25, has now been removed.
996 Use Hooks::run().
997 * The hook 'UnknownAction', deprecated since 1.19, has now been removed.
998 * The hook 'ParserLimitReport', deprecated since 1.22, has been removed. Use
999 the hooks 'ParserLimitReportPrepare' and 'ParserLimitReportFormat' instead.
1000 * The following deprecated API methods have been removed:
1001 * ApiBase::profileIn() (deprecated in 1.25)
1002 * ApiBase::profileOut() (deprecated in 1.25)
1003 * ApiBase::safeProfileOut() (deprecated in 1.25)
1004 * ApiBase::profileDBIn() (deprecated in 1.25)
1005 * ApiBase::profileDBOut() (deprecated in 1.25)
1006 * ApiBase::dieUsage() (deprecated in 1.29)
1007 * ApiBase::dieUsageMsg() (deprecated in 1.29)
1008 * ApiBase::dieUsageMsgOrDebug() (deprecated in 1.29)
1009 * ApiBase::getErrorFromStatus() (deprecated in 1.29)
1010 * ApiBase::parseMsg() (deprecated in 1.29)
1011 * ApiBase::setWarning() (deprecated in 1.29)
1012 * ApiPageSet::getInvalidTitles() (deprecated in 1.26)
1013 * ApiQueryLogEvents::addLogParams() (deprecated in 1.25)
1014 * ApiUsageException::getCodeString() (deprecated in 1.29)
1015 * ApiUsageException::getMessageArray() (deprecated in 1.29)
1016 * Class UsageException, deprecated in 1.29, has been removed.
1017 * MediaWiki no longer has a 'JavaScript-powered' wikitext toolbar built in. The
1018 old "bulletin board style toolbar", known as "the 2006 wikitext editor", has
1019 been removed, and instead sysadmins will be required to choose one (or more)
1020 of the several extensions available for this purpose if they need the
1021 functionality. The MediaWiki "tarball" releases have included the replacement
1022 extension for this, the WikiEditor extension aka "the 2010 wikitext editor",
1023 for many years now. As part of this, several parts of MediaWiki have been
1024 removed or simplified:
1025 * The user option 'showtoolbar' (shown as "Show edit toolbar") is no longer
1026 available; if an extension adds a toolbar via the EditPageBeforeEditToolbar
1027 hook, it will be shown; extensions should provide a specific user preference
1028 to disable themselves as needed.
1029 * The public methods Language::getImageFile() and ::getImageFiles(), and the
1030 related specification of $imageFiles within individual languages' code file,
1031 as well as the referenced static media assets, all of which were only used
1032 inside MediaWiki itself for providing the icons for the old toolbar, have
1033 been removed without explicit deprecation.
1034 * The internal ResourceLoader module "mediawiki.toolbar", which is unused
1035 except by MediaWiki itself and back-compatibility code, has been removed.
1036 * The internal ResourceLoaderEditToolbarModule class has been removed.
1037
1038 === Deprecations in 1.32 ===
1039 * HTMLForm::setSubmitProgressive() is deprecated. No need to call it. Submit
1040 button is already marked as progressive.
1041 * Skin::setupSkinUserCss() is deprecated. Adding of modules to load
1042 has been centralised to Skin::getDefaultModules(), which is now capable
1043 of queueing style modules as well.
1044 * OutputPage::addModuleScripts() and ParserOutput::addModuleScripts are
1045 deprecated. Use addModules() instead.
1046 * Overriding SearchEngine::{searchText,searchTitle,searchArchiveTitle}
1047 in extending classes is deprecated. Extend related doSearch* methods
1048 instead.
1049 * The following 'mediawiki.api' plugin modules were merged into mediawiki.api
1050 and deprecated: mediawiki.api.category, mediawiki.api.edit,
1051 mediawiki.api.login, mediawiki.api.options, mediawiki.api.parse,
1052 mediawiki.api.upload, mediawiki.api.user, mediawiki.api.watch,
1053 mediawiki.api.messages, and mediawiki.api.rollback.
1054 * ApiBase::truncateArray() is deprecated. No replacement, as nothing is known
1055 to use it.
1056 * WatchAction::getUnwatchToken is deprecated. Use WatchAction::getWatchToken
1057 with the 'unwatch' action parameter instead.
1058 * IcuCollation::getICUVersion() is deprecated, as you can just use the PHP
1059 constant INTL_ICU_VERSION directly in all versions that MediaWiki supports.
1060 * Parser::fetchFile() is deprecated. Use ::fetchFileAndTitle() instead.
1061 * The ApiQueryContributions class has been renamed to ApiQueryUserContribs.
1062 * The XMPInfo, XMPReader, and XMPValidate classes have been deprecated in favor
1063 of the namespaced classes provided by the wikimedia/xmp-reader library.
1064 * SearchResultSet::{next,rewind} are deprecated. Calling code should
1065 use foreach on the SearchResultSet, or the extractResults method. Extending
1066 code should override extractResults.
1067 * Instantiating SearchResultSet directly is deprecated. SearchEngine
1068 implementations must subclass SearchResultSet for their purposes.
1069 * SearchResult::setExtensionData argument has been changed from accepting an
1070 array to accepting a Closure that returns the array when called.
1071 * Class CryptRand, everything in MWCryptRand except generateHex() and function
1072 MediaWikiServices::getInstance()->getCryptRand() are deprecated, use
1073 random_bytes() to generate cryptographically secure random byte sequences.
1074 * Parser::getConverterLanguage() is deprecated. Use ::getTargetLanguage()
1075 instead.
1076 * Language::markNoConversion() is deprecated. It confused readers because
1077 it had unexpected behavior (only marking text if it looked like a URL)
1078 and was only used in a single place in the code. Use
1079 LanguageConverter::markNoConversion() instead.
1080 * (T197492) Language::truncate() was soft deprecated in 1.31 and is
1081 hard deprecated in this release. It has been split into two similar
1082 methods, Language::truncateForVisual() and Language::truncateForDatabase(),
1083 which measure length in characters and bytes, respectively. Use
1084 Language::truncateForVisual() when possible to provide equity to users
1085 of multibyte scripts.
1086 * (T176526) EditPage::getContextTitle() falling back to $wgTitle when the
1087 context title is unset is now deprecated; anything creating an EditPage
1088 instance should set the context title via ::setContextTitle().
1089 * The 'jquery.hidpi' module (polyfill for IMG srcset) is deprecated.
1090 * ResourceLoaderStartUpModule::getStartupModules() and ::getLegacyModules()
1091 are deprecated. These concepts are obsolete and have no replacement.
1092 * String type for $lang of DifferenceEngine::setTextLanguage is deprecated.
1093 * The following methods of OutputPage are now deprecated in favour
1094 of using showFatalError directly: OutputPage::showFileDeleteError()
1095 OutputPage::showFileNotFoundError(), OutputPage::showFileRenameError()
1096 OutputPage::showFileCopyError() and OutputPage::showUnexpectedValueError().
1097 * The Replacer, DoubleReplacer, HashtableReplacer, and RegexlikeReplacer
1098 classes are now deprecated. Use a Closure instead.
1099 * (T194263) ContentHandler::makeParserOptions() is deprecated. Use
1100 WikiPage::makeParserOptions() or ParserOptions::newCanonical() instead.
1101 * (T100681) Use of the Parsoid v1 API with the VirtualRESTService, deprecated in
1102 MediaWiki 1.26, is now hard-deprecated. All known clients were converted to
1103 the Parsoid v3 API in May 2015.
1104 * $input is deprecated in hook 'LogEventsListGetExtraInputs'. Use
1105 $formDescriptor instead.
1106 * SearchEngine::transformSearchTerm( $term ) should no longer be called prior
1107 to running searchText. This method was mainly implemented to support the
1108 'prefix' URI param in SpecialSearch, but there are no reasons to expose this
1109 logic as it should be handled internally by SearchEngine implementations
1110 supporting this feature. SearchEngine implementations should no longer
1111 override this methods.
1112 * SearchEngine::replacePrefixes( $query ) should no longer be called prior
1113 to running searchText/searchTitle.
1114 * (T199657) Messages for $wgFilterLogTypes labels should be no longer be in the
1115 'log-show-hide-[type]' format. Instead use 'logeventslist-[type]-log'.
1116 * Global functions wfArrayFilter() and wfArrayFilterByKey() are deprecated.
1117 use array_filter() directly.
1118 * The $wgShowSQLErrors global is deprecated and nonfunctional.
1119 Set $wgShowExceptionDetails and/or $wgShowHostnames instead.
1120 * The $wgShowDBErrorBacktrace global is deprecated and nonfunctional.
1121 Set $wgShowExceptionDetails instead.
1122 * Public access to the DifferenceEngine properties mOldid, mNewid, mOldRev,
1123 mNewRev, mOldPage, mNewPage, mOldContent, mNewContent, mRevisionsLoaded,
1124 mTextLoaded and mCacheHit is deprecated. Use getOldid() / getNewid() /
1125 getOldRevision() / getNewRevision() for the first four (note that the
1126 revision ones return a RevisionRecord, not a Revision), do your own lookup
1127 for page/content.
1128 * The $wgExternalDiffEngine value 'wikidiff2' is deprecated. To use wikidiff2
1129 just enable the PHP extension, and it will be autodetected.
1130 * (T194731) DifferenceEngine properties mOldContent and mNewContent and methods
1131 setContent(), generateContentDiffBody(), generateTextDiffBody() and textDiff()
1132 are deprecated. To interact with a single slot, use a SlotDiffRenderer (and
1133 subclass it to customize diff rendering); to diff custom (e.g. unsaved)
1134 content, use setRevisions(). Subclassing DifferenceEngine should only be done
1135 to customize page-level diff properties (such as the navigation header).
1136 * The wfUseMW function, soft-deprecated in 1.26, is now hard deprecated.
1137 * All MagicWord static methods are now deprecated. Use the MagicWordFactory
1138 methods instead.
1139 * PasswordFactory::init is deprecated. To get a password factory with the
1140 standard configuration, use
1141 MediaWikiServices::getInstance()->getPasswordFactory.
1142 * $wgContLang is deprecated, use
1143 MediaWikiServices::getInstance()->getContentLanguage() instead.
1144 * $wgParser is deprecated, use MediaWikiServices::getInstance()->getParser()
1145 instead.
1146 * wfGetMainCache() is deprecated, use ObjectCache::getLocalClusterInstance()
1147 instead.
1148 * wfGetCache() is deprecated, use ObjectCache::getInstance() instead.
1149 * All SpecialPageFactory static methods are deprecated. Instead, call the
1150 methods on a SpecialPageFactory instance, which may be obtained from
1151 MediaWikiServices.
1152 * mw.user.stickyRandomId was renamed to the more explicit
1153 mw.user.getPageviewToken to better capture its function.
1154 * Passing Revision objects to ContentHandler::getUndoContent() is deprecated,
1155 Content object should be passed instead.
1156 * (T197179) Parameters 'notice', 'notice-messages', 'notice-message',
1157 previously used by OOUI HTMLForm fields, are now deprecated. Use
1158 'help', 'help-message', 'help-messages' instead.
1159 * (T197179) HTMLFormField::getNotices() is now deprecated.
1160 * The jquery.localize module is now deprecated. Use jquery.i18n instead.
1161 * The SecondaryDataUpdates hook was deprecated in favor of RevisionDataUpdates,
1162 or overriding ContentHandler::getSecondaryDataUpdates (T194038).
1163 * The WikiPageDeletionUpdates hook was deprecated in favor of
1164 PageDeletionDataUpdates, or overriding ContentHandler::getDeletionDataUpdates
1165 (T194038).
1166 * Content::getSecondaryDataUpdates has been deprecated in favor of
1167 ContentHandler::getSecondaryDataUpdates() for overriding by extensions
1168 (T194038).
1169 Application logic should call WikiPage::doSecondaryDataUpdates() (T194037).
1170 * Content::getDeletionUpdates has been deprecated in favor of
1171 ContentHandler::getDeletionUpdates() for overriding by extensions (T194038).
1172 Application logic should call WikiPage::doSecondaryDataUpdates() (T194037).
1173 * (T198214) Old Tidy-related configuration settings, which were soft-deprecated
1174 in MediaWiki 1.26, have now been hard deprecated. This affects $wgUseTidy,
1175 $wgTidyBin, $wgTidyConf, $wgTidyOpts, $wgTidyInternal, and $wgDebugTidy. Use
1176 $wgTidyConfig instead.
1177 * All Tidy configurations other than Remex have been hard deprecated;
1178 future parsers will not emit compatible output for these configurations.
1179 In particular, running MediaWiki with tidy disabled has been deprecated.
1180 * (T198214) OutputPage::addWikiText(), OutputPage::addWikiTextWithTitle(),
1181 and OutputPage::addWikiTextTitle() have been deprecated, since they
1182 can result in untidy output. In addition OutputPage::addWikiTextTidy()
1183 and OutputPage::addWikiTextTitleTidy() was deprecated to make naming new
1184 methods consistent. Use OutputPage::addWikiTextAsInterface() or
1185 OutputPage::addWikiTextAsContent() instead, which ensures the output is
1186 tidy and clarifies whether content-language specific postprocessing should
1187 be done on the text.
1188 * OutputPage::parse() and OutputPage::parseInline() have been deprecated
1189 due to untidy output and inconsistent handling of wrapper divs and
1190 interface/content language defaults. Use OutputPage::parseAsContent(),
1191 OutputPage::parseAsInterface(), or OutputPage::parseInlineAsInterface()
1192 as appropriate.
1193 * QuickTemplate::msgHtml() and BaseTemplate::msgHtml() have been deprecated
1194 as they promote bad practises. I18n messages should always be properly
1195 escaped.
1196 * Skin::getDynamicStylesheetQuery() has been deprecated. It always
1197 returns action=raw&ctype=text/css which callers should use directly.
1198 * Class LegacyFormatter is deprecated.
1199 * Use of CommentStore::insertWithTempTable() with 'img_description' is
1200 deprecated. Use CommentStore::insert() instead.
1201 * Language::setCode is deprecated as public function. Use Language::factory
1202 to create a new Language object with a different language code.
1203 * Several classes have been moved from the MediaWiki\Storage\ namespace to the
1204 MediaWiki\Revision\ namespace. The old class names are aliased for
1205 compatibility, but are deprecated. Classes are IncompleteRevisionException,
1206 MutableRevisionRecord, MutableRevisionSlots, RevisionAccessException,
1207 RevisionArchiveRecord, RevisionFactory, RevisionLookup, RevisionRecord,
1208 RevisionSlots, RevisionStore, RevisionStoreRecord, SlotRecord, and
1209 SuppressedDataException.
1210 * When using OOUI HTMLForm containing an 'info' field which uses the 'rawrow'
1211 option, it is now deprecated to give its contents (the 'default' option)
1212 as a string. They should be given as a OOUI\FieldLayout object instead.
1213 Notably, this affects fields defined in the 'GetPreferences' hook, because
1214 Special:Preferences uses an OOUI form now. (If possible, don't use 'rawrow'.)
1215 * In Skin::doEditSectionLink omitting the parameters $tooltip and $lang is
1216 deprecated. For the $lang parameter, types other than Language are
1217 deprecated.
1218 * The $wgUseKeyHeader configuration option and the
1219 OutputPage::getKeyHeader() method have been deprecated; the relevant
1220 draft IETF spec expired without becoming a standard.
1221 * Deprecated API action=query&prop=info inprop=readable in favor of
1222 intestactions=read.
1223
1224 === Other changes in 1.32 ===
1225 * (T198811) The following tables have had their UNIQUE indexes turned into
1226 proper PRIMARY KEYs for increased maintainability: interwiki, page_props,
1227 protected_titles and site_identifiers.
1228 * OOUI HTMLForm will now display help text inline after the input field,
1229 rather than in a popup. Previous behavior can be restored by using
1230 `'help-inline' => false`.
1231 * The archive table's ar_rev_id field is now unique.
1232 * Special:BotPasswords now requires reauthentication.
1233 * (T174023) Multi-Content Revision (MCR) capabilities were introduced into the
1234 storage layer and have basic support for display. No user interface exists
1235 yet for creating or managing content in slots beides the main slot. See
1236 <https://www.mediawiki.org/wiki/Multi-Content_Revisions> for more
1237 information.
1238 * The image_comment_temp database table has been removed. Since all access
1239 should be mediated by the CommentStore class, this change shouldn't affect
1240 external code.
1241 * (T206147) Database::close() will no longer commit any open transactions.
1242 * (T64103) Dropped columns category.cat_hidden, site_stats.ss_admins, and
1243 recentchanges.rc_cur_time from the PostgreSQL schema.
1244
1245 = MediaWiki 1.31 =
1246
1247 == MediaWiki 1.31.3 ==
1248
1249 This is a maintenance release of the MediaWiki 1.31 branch.
1250
1251 === Changes since MediaWiki 1.31.2 ===
1252 * (T225558) Update installer link to PHP intl.
1253 * (T225496) Detect APC for MainCacheType in CLI installer.
1254 * (T226766) Remove jetbrains/phpstorm-stubs from composer dev dependancies.
1255 * (T202211) Fix SQLite patch-(image|page|template)links-fix-pk.sql column order.
1256
1257 == MediaWiki 1.31.2 ==
1258
1259 This is a security and maintenance release of the MediaWiki 1.31 branch.
1260
1261 Required PHP version has been increased from 7.0.0 to 7.0.13.
1262
1263 === Changes since MediaWiki 1.31.1 ===
1264 * (T204729) WatchedItemStore::countVisitingWatchersMultiple() shouldn't query
1265 all titles when asked for none.
1266 * (T205967) Fix syntax error typo in postgres database upgrade file.
1267 * (T200254) Add pear/Net_SMTP 1.7.3 to composer dependencies.
1268 * (T206765) Load installer i18n when running update.php.
1269 * (T109121) Remove deprecated pear/mail_mime-decode from composer suggested
1270 libraries.
1271 [Also in the bundled composer /vendor directory.]
1272 * Various PHP 7.2 and 7.3 compatibility fixes:
1273 * (T200595, T206974) Fix PHP 7.3 warnings of using "continue" in some
1274 scenarios instead of "break".
1275 * (T206976, T206977) Also in the bundled LocalisationUpdate and
1276 ParserFunctions extensions.
1277 * (T206979) Fix PHP 7.3 warnings of using "compact()" when some variables may
1278 not be set.
1279 * (T215632) FormatMetadata and UploadStash regexes fixed to be PHP
1280 7.3-compatible.
1281 * Fix PHP warnings "preg_replace(): [...] invalid range in character class.
1282 * Avoid PHP 7.2 warnings in DBConRefTest about count() on non-Countable.
1283 * Suppress "Headers already sent" in PHP 7.2 too.
1284 * (T206476) Output only to stderr in unit tests.
1285 * (T207112) Add session_write_close() calls to SessionManager tests.
1286 * oyejorge/less.php replaced with our fork wikimedia/less.php
1287 * (T209756) Updated wikimedia/ip-set from 1.2.0 to 1.3.0.
1288 * (T213489) Avoid session double-start in Setup.php.
1289 * (T206975) Switch to our fork of less.php.
1290 * (T207540) Include IP address in "Login for $1 succeeded" log entry.
1291 * (T201781) Database: Allow selectFieldValues() to accept SQL fragments.
1292 * (T205765) installer: Don't link to the obsolete "Extension Matrix" page.
1293 * (T206013) Update ImportableUploadRevisionImporter for interwiki usernames.
1294 * (T207541) Pass an email address, not a MailAddress, to mail().
1295 * (T207603) SECURITY: User JS may no longer be loaded with mime type
1296 text/javascript if there is no account associated with the username.
1297 * (T112937, T113042) SECURITY: Do not allow loading pages raw with a
1298 text/javascript MIME
1299 type if non-admins can edit the page.
1300 * (T17491) <ins>/<del> elements can be phrasing or flow.
1301 * (T200827) RemexCompatMunger: Don't call endTag() in case B/b
1302 * (T207088) Upgrade wikimedia/remex-html to 2.0.1.
1303 [Also in the bundled composer /vendor directory.]
1304 * (T194052) Updated wikimedia/base-convert from 1.0.1 to 2.0.0.
1305 [Also in the bundled composer /vendor directory.]
1306 * (T199494) Fix notices in maintenance/removeUnusuedAccounts.php.
1307 * Require ext-fileinfo in composer.json, per PHPVersionCheck.
1308 * (T176390) Bundled LocalisationUpdate extension: Handle exceptions from
1309 GitHubFetcher.
1310 * (T208255) Completion search should not change the search query.
1311 * (T209870) Fix SQL syntax error in MS-SQL initialisation file for new wikis.
1312 * (T185049) LogFormatter: Fail softer when trying to link an invalid titles.
1313 * (T210998) Properly set $wgLanguageCode in the generated LocalSettings.php
1314 if --lang is used with the command-line installer (install.php).
1315 * (T211061) ImageListPager: Actor migration for buildQueryConds().
1316 * (T209335) Clarify the default sidebar 'Help' link is about MediaWiki itself.
1317 * Fix addition of ug_expiry column to user_groups table on MSSQL.
1318 * (T204767) Add join conditions to ActiveUsersPager.
1319 * (T210621) User: Bypass repeatable-read when creating an actor_id.
1320 * (T204531) rdbms: reduce LoadBalancer replication log spam.
1321 * (T195525) Fix db error outage page.
1322 * (T208871) The hard-coded Google search form on the database error page was
1323 removed.
1324 * (T176097) Fix flaky MessageBlobStoreTest assertion failures.
1325 * (T209423) Update required PHP version to 7.0.13.
1326 * (T209885) Prevent populateSearchIndex.php from breaking once actor migration
1327 has been started.
1328 * (T216968) Return pageid as int in both list=iwbacklinks and
1329 list=langbacklinks.
1330 * (T215169) Fix for Database::update() with IGNORE option fails on PostgreSQL.
1331 * (T204423) Backport support for hyphenated DB names in JobQueueGroup.
1332 * (T199474) Fix typo in rebuildrecentchanges.php resulting in rogue flags.
1333 * (T218608) SECURITY: Fix an issue that prevents Extension:OAuth working when
1334 $wgBlockDisablesLogin is true.
1335 * (T216029) Chrome redirects to Special:BadTitle after editing a section with
1336 a non-Latin name on a page with non-Latin characters in title.
1337 * (T219728) Added support for new Japanese era name "Reiwa".
1338 * (T25227) SECURITY: action=logout now requires to be posted and have a csrf
1339 token.
1340 * Updated cssjanus/cssjanus from 1.2.0 to 1.3.0.
1341 * (T222385) resourceloader: Use AND instead of OR for upsert conds in
1342 saveFileDependencies().
1343 * (T224374) Fix message parameters so that the message that says SQLite is out
1344 of date makes sense.
1345 * SpecialPage::checkLoginSecurityLevel() will now preserve POST data when
1346 reauthenticating.
1347 * FormSpecialPage::execute() will now call checkLoginSecurityLevel() if
1348 getLoginSecurityLevel() returns non-false.
1349 * (T197279) SECURITY: Fix reauth in Special:ChangeEmail.
1350 * (T208881) SECURITY: blacklist CSS var().
1351 * (T209794) SECURITY: rate-limit and prevent blocked users from changing email.
1352 * (T199540) SECURITY: API: Respect $wgBlockCIDRLimit in action=block.
1353 * (T212118) SECURITY: Fix cache mode for (un)patrolled recent changes query.
1354 * (T222036, T222038) SECURITY: Add permission check for user is permitted to
1355 view the log type.
1356 * (T221739) SECURITY: resources: Patch jQuery 3.2.1 for CVE-2019-11358.
1357
1358 == MediaWiki 1.31.1 ==
1359
1360 This is a security and maintenance release of the MediaWiki 1.31 branch.
1361
1362 === Changes since MediaWiki 1.31.0 ===
1363 * (T169545, CVE-2018-0503) SECURITY: $wgRateLimits entry for 'user' overrides
1364 'newbie'.
1365 * (T194605, CVE-2018-0505) SECURITY: BotPasswords can bypass CentralAuth's
1366 account lock.
1367 * (T199029, CVE-2018-13258) SECURITY: Tarball was missing .htaccess files.
1368 * (T197229) Bundle Nuke extension, it was accidentally omitted.
1369 * (T193995) Fix undefined patchPath() method call in parser tests.
1370 * (T198687) Fix various selectFields methods to use the string 'NULL', not null.
1371 * Special:BotPasswords now requires reauthentication.
1372 * (T191608, T187638) Add 'logid' parameter to Special:Log.
1373 * (T193829) Indicate when a Bot Password needs reset.
1374 * (T198037) GitInfo: Don't try shelling out if it's disabled.
1375 * (T151415) Log email changes.
1376 * (T197206) Fix performance regression when multiple DB used without caching.
1377 * (T197030) PHPSessionHandler: Suppress headers warnings in initialize().
1378 * (T182377, T196793) Exif: Guard against uncountable tag values.
1379 * (T200861) Fix total breakage of SQLite web upgrade.
1380 * (T200864) Fix pingback over-reporting on non-MySQL databases
1381 * (T202550) Unbreak SpecialListusersHeaderForm and SpecialListusersHeader
1382 hooks.
1383
1384 == MediaWiki 1.31.0 ==
1385
1386 === Changes since MediaWiki 1.31.0-rc.2 ===
1387 * (T195783) Initialize PSR-4 namespaces at same stage as normal autoloader.
1388 * (T196092) Hide MySQL binary/utf-8 charset option in the installer.
1389 * (T196185) Don't allow setting $wgDBmysql5 in the installer.
1390 * (T196125) php-memcached 3.0 (provided with PHP 7.0) is now supported.
1391 * (T182366) UploadBase::checkXMLEncodingMissmatch() now works on PHP 7.1+
1392 * (T118683) Fix exception from &$user deref on HHVM in the TitleMoveComplete
1393 hook.
1394 * (T196672) The mtime of extension.json files is now able to be zero
1395 * (T180403) Validate $length in padleft/padright parser functions.
1396 * (T143790) Make $wgEmailConfirmToEdit only affect edit actions.
1397
1398 === Changes since MediaWiki 1.31.0-rc.0 ===
1399 * (T33223) Drop archive.ar_text and ar_flags.
1400 * Add default edit rate limit of 90 edits/minute for all users.
1401 * (T187645) Use codepoint as tiebreaker when getting first-letters in
1402 IcuCollation.
1403 * (T191947) Don't shell during the installer if shelling out is disabled.
1404 * (T194319) Improve duplicate config setting exception as part of extension
1405 registration.
1406 * (T195211) Don't require trailing slash in PSR-4 autoloader directory.
1407 * (T186565) Fix PHP Notice from `ob_end_flush()` in `FileRepo::streamFile()`.
1408 * Do not incorrectly hide namespace input field in the installer.
1409 * (T186456) Refactor checks looking for PEAR maik libraries to be clearer.
1410
1411 === Important pre-upgrade notes for 1.31 ===
1412 * If you're using MySQL, SQLite, or MSSQL, are not using update.php to apply
1413 schema changes, and cannot have downtime to run migrateArchiveText.php and
1414 apply patch-drop-ar_text.sql manually, you'll have to apply a default value
1415 to the ar_text and ar_flags columns of the archive table or make those
1416 columns nullable before upgrading to MediaWiki 1.31.
1417 maintenance/archives/patch-nullable-ar_text.sql shows how to do this for
1418 MySQL.
1419
1420 === Configuration changes in 1.31 ===
1421 * $wgEnableAPI and $wgEnableWriteAPI are now deprecated and will be removed in
1422 a future version. The API is now considered to be stable, secure and
1423 essential.
1424 * $wgUsejQueryThree was removed, as it is now the default. This was documented
1425 as a temporary variable during the migration period, deprecated since 1.29.
1426 * $wgLogoHD has been updated to support svg images and uses $wgLogo where
1427 possible for fallback images such as png.
1428 * (T44246) $wgFilterLogTypes will no longer ignore 'patrol' when user does not
1429 have the right to mark things patrolled.
1430 * Wikis that contain imported revisions or CentralAuth global blocks should run
1431 maintenance/cleanupUsersWithNoId.php.
1432 * The configuration settings $wgResourceLoaderMinifierStatementsOnOwnLine and
1433 $wgResourceLoaderMinifierMaxLineLength, deprecated since 1.27, were removed.
1434 * (T180921) $wgReferrerPolicy now supports having fallbacks for browsers that
1435 are not using the latest version of the Referrer Policy specification.
1436 * $wgFragmentMode is now set to [ 'legacy', 'html5' ] by default. This is a
1437 first step of migration to human-readable section IDs that will later result
1438 in 'html5' being the default mode.
1439 * CACHE_ACCEL now only supports APC(u) or WinCache. XCache support was removed
1440 as upstream is inactive and has no plans to move to PHP 7.
1441 * The old CategorizedRecentChanges feature, including its related configuration
1442 option $wgAllowCategorizedRecentChanges, has been removed.
1443 * (T188472) The 'comma' value for $wgArticleCountMethod is no longer supported
1444 for performance reasons, and installations with this setting will now work as
1445 if it was configured with 'any'.
1446 * (T185753) MediaWiki now defaults to using RemexHtml to tidy up user input,
1447 rather than being off by default. If you wish to disable HTML tidying
1448 entirely, set $wgTidyConfig to null; if you wish to use the old, deprecated
1449 Tidy external binary, both set $wgTidyConfig to null and $wgUseTidy to true.
1450 * $wgLogAutopatrol now defaults to false instead of true.
1451 * $wgValidateAllHtml was removed and will be ignored.
1452 * $wgScriptExtension, deprecated and ignored since 1.25, was removed. See the
1453 1.25 release notes for more information.
1454 * $wgUseAjax is now marked as deprecated, just like the deprecated AJAX
1455 framework that it enables. Some extensions mistakenly used this to check
1456 whether any AJAX functionality at all should be enabled, further making this
1457 problematic to retain.
1458 * $wgDBmysql5 is now deprecated, and will be removed in a future version. It
1459 has been marked as experimental ever since it was introduced.
1460
1461 === New features in 1.31 ===
1462 * (T76554) User sub-pages named ….json are now protected in the same way that
1463 ….js and ….css pages are, so that configuration options can safely be placed
1464 there.
1465 * Wikimedia\Rdbms\IDatabase->select() and similar methods now support joins
1466 with parentheses for grouping.
1467 * As a first pass in standardizing dialog boxes across the MediaWiki product,
1468 Html class now provides helper methods for messageBox, successBox, errorBox
1469 and warningBox generation.
1470 * (T9240) Imports will now record unknown (and, optionally, known) usernames in
1471 a format like "iw>Example".
1472 * (T20209) Linker (used on history pages, log pages, and so on) will display
1473 usernames formed like "iw>Example" as interwiki links, as if by wikitext like
1474 [[iw:User:Example|iw>Example]].
1475 * (T111605) The 'ImportHandleUnknownUser' hook allows extensions to auto-create
1476 users during an import.
1477 * Added a hook, ParserOutputPostCacheTransform, to allow extensions to affect
1478 the ParserOutput::getText() post-cache transformations.
1479 * Added a hook, UploadForm:getInitialPageText, to allow extensions to alter the
1480 initial page text for file uploads.
1481 * (T181651) The info page for File pages now displays the file's base-16 SHA1
1482 hash value in the table of basic information.
1483 * Style tags with a 'data-mw-deduplicate' attribute will be deduplicated as a
1484 ParserOutput::getText() post-cache transformation. This may be disabled by
1485 passing 'deduplicateStyles' => false to that method.
1486 * The identity of the logged-in or IP "actor" for logged actions is being moved
1487 into a new actor table, with the rows in tables such as revision and logging
1488 referring to the actor ID instead of storing the user ID and name/IP in
1489 every row.
1490 * This is currently gated by $wgActorTableSchemaMigrationStage. Most wikis
1491 can set this to MIGRATION_NEW and run maintenance/migrateActors.php as
1492 soon as any necessary extensions are updated.
1493 * Most code accessing rows for logged actions from the database should use
1494 the relevant getQueryInfo() methods to get the information needed to build
1495 the SQL query. The ActorMigration class may also be used to get feature
1496 -flagged information needed to access actor-related fields during the
1497 migration period.
1498 * Added Wikimedia\Rdbms\IDatabase::cancelAtomic(), to roll back an atomic
1499 section without having to roll back the whole transaction.
1500 * Wikimedia\Rdbms\IDatabase::doAtomicSection(), non-native ::insertSelect(),
1501 and non-MySQL ::replace() and ::upsert() no longer roll back the whole
1502 transaction on failure.
1503 * (T189785) Added a monthly heartbeat ping to the pingback feature.
1504 * The CLI installer (maintenance/install.php) learned to detect and include
1505 extensions. Pass --with-extensions to enable that feature.
1506 * (T184791) rc_patrolled now has three states: "0" for unpatrolled,
1507 "1" for manually patrolled and "2" for autopatrolled actions.
1508 * Extensions can now set their type to "editor" if they provide an editor or
1509 enhance the editing experience.
1510 * Extensions can use a PSR-4 autoloader by setting an "AutoloadNamespaces"
1511 property in extension.json. See the documentation at
1512 <https://mediawiki.org/wiki/Manual:Extension.json/Schema#AutoloadNamespaces>
1513 for more details and an example.
1514 * (T19099) Tabs which link to pages that don't exist (like those to uncreated
1515 discussion pages) now have a tooltip to indicate state, not just colour.
1516
1517 === External library changes in 1.31 ===
1518 * pear/mail, pear/mail_mime and pear/mail_mime-decode have been moved from
1519 suggested to required. These packages now must be installed via composer
1520 and not via PEAR itself.
1521
1522 ==== Upgraded external libraries ====
1523 * Updated jquery.chosen from v0.9.14 to v1.8.2.
1524 * Updated composer/spdx-licenses from 1.1.4 to 1.3.0 (development dependency).
1525 * Updated nikic/php-parser from 2.1.0 to 3.1.3 (development dependency).
1526 * Updated wikimedia/ip-set from 1.1.0 to 1.2.0.
1527 * Updated wikimedia/relpath from 2.0.0 to 2.1.1.
1528 * Updated wikimedia/running-stat from 1.1.0 to 1.2.0.
1529 * Updated wikimedia/wrappedstring from 2.2.0 to 2.3.0.
1530 * Updated mediawiki/at-ease from 1.1.0 to 1.2.0.
1531 * Updated wikimedia/php-session-serializer from 1.0.4 to 1.0.6.
1532 * Updated wikimedia/remex-html from 1.0.2 to 1.0.3.
1533 * Updated wikimedia/html-formatter from 1.0.1 to 1.0.2.
1534
1535 ==== New external libraries ====
1536 * Added wikimedia/object-factory 1.0.0
1537
1538 ==== Removed and replaced external libraries ====
1539 * (T17845) The deprecated 'jquery.badge' module was removed.
1540 * The deprecated 'jquery.autoEllipsis' module was removed. Use the CSS
1541 text-overflow property instead.
1542 * The deprecated 'jquery.placeholder' module was removed.
1543 * The deprecated 'jquery.appear' module was removed. Use the
1544 'mediawiki.viewport' module instead.
1545 * mediawiki/at-ease was replaced with wikimedia/at-ease.
1546
1547 === Bug fixes in 1.31 ===
1548 * (T90902) Non-breaking space in header ID breaks anchor.
1549 * (T189375) CSSMin now allows quoted urls in `url()` syntax to start with a
1550 space.
1551 * (T2087, T10897, T87753, T174639) Whitespace created by category and language
1552 links is now stripped rather than leaving blank lines in odd places.
1553 * (T3780) Uploads with UTF-8 names now work on PHP7.1+ on Windows servers.
1554 * (T182366) UploadBase::checkXMLEncodingMissmatch() now works on PHP 7.1+
1555
1556 === Action API changes in 1.31 ===
1557 * (T185058) The 'name' value to tgprop for action=query&list=tags has been
1558 removed. It has never made a difference in the output, the name was always
1559 returned regardless.
1560 * The 'watch' and 'unwatch' parameters for action=move have been removed. They
1561 were deprecated and also accidentally nonfunctional since 1.17 in 2010. Use
1562 'watchlist' instead.
1563
1564 === Action API internal changes in 1.31 ===
1565 * ApiBase::getProfileDBTime, deprecated since 1.25, was removed.
1566 * ApiBase::getModuleProfileName, deprecated since 1.25, was removed.
1567 * ApiBase::getProfileTime, deprecated since 1.25, was removed.
1568
1569 === Languages updated in 1.31 ===
1570 MediaWiki supports over 350 languages. Many localisations are updated
1571 regularly. Below only new and removed languages are listed, as well as
1572 changes to languages because of Phabricator reports.
1573
1574 * (T180052) Mirandese (mwl) now supports gendered NS_USER/NS_USER_TALK.
1575 * (T182305) New language support: Nyungar (nys).
1576 * (T186359) New language support: Siberian Tatar [cебертатар] (sty).
1577 * (T186635) New language support: Guianan Creole (gcr).
1578 * (T186647) New language support: Kumyk [къумукъ] (kum).
1579 * (T187750) New language support: Spanish formal address (es-formal).
1580 * (T187824) New language support: Hungarian formal address (hu-formal).
1581 * (T189127) New language support: Gorontalo (gor).
1582
1583 === Breaking changes in 1.31 ===
1584 * MessageBlobStore::insertMessageBlob(), deprecated in 1.27, was removed.
1585 * The OutputPage class constructor now requires a context parameter.
1586 Instantiating without context was deprecated in 1.18.
1587 * The mw.page JavaScript singleton, deprecated in 1.30, was removed.
1588 * Article::getLastPurgeTimestamp(), WikiPage::getLastPurgeTimestamp(), and the
1589 related WikiPage::PURGE_* constants, deprecated in 1.29, were removed.
1590 * The Article::selectFields(), ::onArticleCreate(), ::onArticleDelete(), and
1591 ::onArticleEdit() methods, deprecated in 1.24, were removed.
1592 * Installer::locateExecutable() and ::locateExecutableInDefaultPaths() were
1593 removed. Use ExecutableFinder::findInDefaultPaths() instead.
1594 * The deprecated MW_DIFF_VERSION constant was removed.
1595 DifferenceEngine::MW_DIFF_VERSION should be used instead.
1596 * Due to significant refactoring, method ContribsPager::getUserCond() that had
1597 no access restriction has been removed.
1598 * The Block class will no longer accept usable-but-missing usernames for
1599 'byText' or ->setBlocker(). Callers should either ensure the blocker exists
1600 locally or use a new interwiki-format username like "iw>Example".
1601 * The following methods and constants from the WatchedItem class, which were
1602 deprecated in 1.27, have been removed:
1603 * WatchedItem::getTitle()
1604 * WatchedItem::fromUserTitle()
1605 * WatchedItem::addWatch()
1606 * WatchedItem::removeWatch()
1607 * WatchedItem::isWatched()
1608 * WatchedItem::duplicateEntries()
1609 * WatchedItem::IGNORE_USER_RIGHTS
1610 * WatchedItem::CHECK_USER_RIGHTS
1611 * WatchedItem::DEPRECATED_USAGE_TIMESTAMP
1612 * The $statementsOnOwnLine parameter of JavaScriptMinifier::minify was removed.
1613 $wgResourceLoaderMinifierStatementsOnOwnLine, the corresponding configuration
1614 variable, has been deprecated since 1.27 and was removed as well.
1615 * The $maxLineLength parameter of JavaScriptMinifier::minify was removed.
1616 $wgResourceLoaderMinifierMaxLineLength, the corresponding configuration
1617 variable, has been deprecated since 1.27 and was removed as well.
1618 * The HtmlFormatter class, deprecated in 1.27, was removed. The namespaced
1619 HtmlFormatter\HtmlFormatter class should be used instead.
1620 * The driver 'mysql' for MySQL, deprecated in MediaWiki 1.30, has been removed.
1621 The driver has been deprecated since PHP 5.5 and was removed in PHP 7.0. The
1622 default driver for MySQL has been 'mysqli' since MediaWiki 1.22.
1623 * The following properties of PreparedEdit were deprecated in 1.21 and have
1624 been removed:
1625 * PreparedEdit->newText
1626 * PreparedEdit->oldText
1627 * PreparedEdit->pst
1628 * ParserOutput objects which are generated using a non-default value for
1629 ParserOptions::setWrapOutputClass() can no longer be added to the parser
1630 cache.
1631 * The following deprecated methods from the OutputPage class have been removed:
1632 * OutputPage::addExtensionStyle(); deprecated in 1.27
1633 * OutputPage::getExtStyle(); deprecated in 1.27
1634 * OutputPage::setETag(); deprecated in 1.28 (obsolete no-op)
1635 * OutputPage::setSquidMaxage(); deprecated in 1.27
1636 * OutputPage::readOnlyPage(); deprecated in 1.25
1637 * OutputPage::rateLimited(); deprecated in 1.25
1638 * Additionally, the protected OutputPage::$mExtStyles array, only accessed
1639 through the above and with no known uses, was removed.
1640 * The no-op method Skin::showIPinHeader(), deprecated in 1.27, was removed.
1641 * The following variables and methods in EditPage, deprecated in MediaWiki 1.30,
1642 were removed:
1643 * $isCssJsSubpage — use ::isUserConfigPage()
1644 * $isCssSubpage — use ::isUserCssConfigPage()
1645 * $isJsSubpage — use ::isUserJsConfigPage()
1646 * $isWrongCaseCssJsPage – use ::isWrongCaseUserConfigPage()
1647 * ::getSummaryInput() – use ::getSummaryInputWidget()
1648 * ::getSummaryInputOOUI() – use ::getSummaryInputWidget()
1649 * ::getCheckboxes() – use ::getCheckboxesWidget() or
1650 ::getCheckboxesDefinition()
1651 * ::getCheckboxesOOUI() – use ::getCheckboxesWidget() or
1652 ::getCheckboxesDefinition()
1653 * ResourceLoaderModule::getPosition(), deprecated in 1.29, has been removed.
1654 * In User, the cookie-related methods which were wrappers for the functions on
1655 the response object, and were deprecated in 1.27, have been removed:
1656 * ::setCookie()
1657 * ::clearCookie()
1658 * ::setExtendedLoginCookie()
1659 Note that User::setCookies() remains, and is not deprecated.
1660 * Also in User, some auth-related methods which were deprecated in 1.27 have
1661 been removed:
1662 * ::getEditTokenTimestamp() – use MediaWiki\Session\Token::getTimestamp()
1663 * ::getPasswordFactory() – create a PasswordFactory directly
1664 * ::passwordChangeInputAttribs()
1665 * The global functions wfProfileIn and wfProfileOut, deprecated in 1.25, have
1666 been removed.
1667 * SpecialPageFactory::getList(), deprecated in 1.24, has been removed. You can
1668 use ::getNames() instead.
1669 * OpenSearch::getOpenSearchTemplate(), deprecated in 1.25, has been removed. You
1670 can use ApiOpenSearch::getOpenSearchTemplate() instead.
1671 * The global function wfBaseConvert, deprecated in 1.27, has been removed. Use
1672 Wikimedia\base_convert() directly.
1673 * Calling Database::begin() explicitly during an implicit transaction or when
1674 DBO_TRX is set results in an exception. Calling Database::commit() explicitly
1675 for an implicit transaction also results in an exception. Previously these
1676 were logged as errors. The startAtomic() and endAtomic() methods, or
1677 AtomicSectionUpdate should be used instead.
1678 * The global function wfOutputHandler() was removed, use the its replacement
1679 MediaWiki\OutputHandler::handle() instead. The global function was only
1680 sometimes defined. Its replacement is always available via the autoloader.
1681 * ChangeTags::listExtensionActivatedTags and ::listExtensionDefinedTags,
1682 deprecated in 1.28, have been removed. Use ::listSoftwareActivatedTags() and
1683 ::listSoftwareDefinedTags() instead.
1684 * Title::getTitleInvalidRegex(), deprecated in 1.25, has been removed. You can
1685 use MediaWikiTitleCodec::getTitleInvalidRegex() instead.
1686 * HTMLForm & VFormHTMLForm::isVForm(), deprecated in 1.25, have been removed.
1687 * The ProfileSection class, deprecated in 1.25 and unused, has been removed.
1688 * The ResourceLoaderGetLessVars hook, deprecated in 1.30, has been removed. Use
1689 ResourceLoaderModule::getLessVars() to expose local variables instead of
1690 global ones.
1691 * As part of work to modernise user-generated content clean-up, a config option
1692 and some methods related to HTML validity were removed without deprecation.
1693 The public methods MWTidy::checkErrors() and the path through which it was
1694 called, TidyDriverBase::validate(), are removed, as are the testing methods
1695 MediaWikiTestCase::assertValidHtmlSnippet() and ::assertValidHtmlDocument().
1696 The $wgValidateAllHtml configuration option is removed and will be ignored.
1697 * Execution of external programs using MediaWiki\Shell\Command now applies
1698 the RESTRICT_DEFAULT Firejail restriction by default.
1699 * The ResourceLoaderModule::getHashMtime() and ::getDefinitionMtime() methods,
1700 deprecated in 1.26, were removed.
1701 * The deprecated 'mediawiki.widgets.CategorySelector' module alias was removed.
1702 Use the 'mediawiki.widgets.CategoryMultiselectWidget' module directly.
1703
1704 === Deprecations in 1.31 ===
1705 * The Revision class was deprecated in favor of RevisionStore, BlobStore, and
1706 RevisionRecord and its subclasses.
1707 * The global function wfBCP47 is deprecated in favour of LanguageCode::bcp47.
1708 * The global function wfCountDown is now deprecated in favor of
1709 Maintenance::countDown.
1710 * Several methods for returning lists of fields to select from the database
1711 have been deprecated in favor of similar methods that also return the tables
1712 to select from and the join conditions for those tables.
1713 * Block::selectFields() → Block::getQueryInfo()
1714 * RecentChange::selectFields() → RecentChange::getQueryInfo()
1715 * ArchivedFile::selectFields() → ArchivedFile::getQueryInfo()
1716 * LocalFile::selectFields() → LocalFile::getQueryInfo()
1717 * LocalFile::getCacheFields() with a prefix no longer works
1718 * LocalFile::getLazyCacheFields() with a prefix no longer works
1719 * OldLocalFile::selectFields() → OldLocalFile::getQueryInfo()
1720 * RecentChange::selectFields() → RecentChange::getQueryInfo()
1721 * Revision::userJoinCond() → Revision::getQueryInfo( [ 'user' ] )
1722 * Revision::selectUserFields() → Revision::getQueryInfo( [ 'user' ] )
1723 * Revision::pageJoinCond() → Revision::getQueryInfo( [ 'page' ] )
1724 * Revision::selectPageFields() → Revision::getQueryInfo( [ 'page' ] )
1725 * Revision::selectTextFields() → Revision::getQueryInfo( [ 'text' ] )
1726 * Revision::selectFields() → Revision::getQueryInfo()
1727 * Revision::selectArchiveFields() → Revision::getArchiveQueryInfo()
1728 * User::selectFields() → User::getQueryInfo()
1729 * WikiPage::selectFields() → WikiPage::getQueryInfo()
1730 * Revision::setUserIdAndName() was deprecated.
1731 * Access to TitleValue class properties was deprecated, the relevant getters
1732 should be used instead.
1733 * DifferenceEngine::getDiffBodyCacheKey() is deprecated. Subclasses should
1734 override DifferenceEngine::getDiffBodyCacheKeyParams() instead.
1735 * Use of Maintenance::error( $err, $die ) to exit script was deprecated. Use
1736 Maintenance::fatalError() instead.
1737 * Passing a ParserOptions object to OutputPage::parserOptions() is deprecated.
1738 * The RevisionInsertComplete hook is now deprecated; use instead the hook
1739 RevisionRecordInserted. RevisionInsertComplete is still called, but the second
1740 and third parameter will always be null. Hard deprecation is scheduled for
1741 1.32.
1742 * The following methods that get and set ParserOutput state are deprecated.
1743 Callers should use the new stateless $options parameter to
1744 ParserOutput::getText() instead.
1745 * ParserOptions::getEditSection()
1746 * ParserOptions::setEditSection()
1747 * ParserOutput::getEditSectionTokens()
1748 * ParserOutput::setEditSectionTokens()
1749 * ParserOutput::getTOCEnabled()
1750 * ParserOutput::setTOCEnabled()
1751 * OutputPage::enableSectionEditLinks()
1752 * OutputPage::sectionEditLinksEnabled()
1753 * The public ParserOutput state fields $mTOCEnabled and $mEditSectionTokens
1754 are also deprecated.
1755 * License::getLicenses has been deprecated; use License::getLines instead.
1756 * QuickTemplate::setRef() was deprecated in favour of QuickTemplate::set().
1757 Setting template variables by reference allowed violating the principle of
1758 data being immutable once added to the skin template. In practice, this method
1759 was not being used for that. Rather, setRef() existed as memory optimisation
1760 for PHP 4.
1761 * QuickTemplate::setTranslator() and MediaWikiI18N::set() were deprecated in
1762 favour of Skin::msg() parameters.
1763 * MediaWikiI18N::translate() was deprecated in favour of Skin::msg() or
1764 wfMessage().
1765 * Passing false to ParserOptions::setWrapOutputClass() is deprecated. Use the
1766 'unwrap' transform to ParserOutput::getText() instead.
1767 * \ObjectFactory (no namespace) is deprecated, the namespaced class
1768 \Wikimedia\ObjectFactory from the wikimedia/object-factory library should be
1769 used instead.
1770 * CommentStore::newKey is deprecated. Instead, get an instance from
1771 MediaWikiServices.
1772 * The following CommentStore methods have had their signatures changed to
1773 introduce a $key parameter, usage of the methods on instances retrieved from
1774 CommentStore::newKey will remain unchanged but deprecated:
1775 * CommentStore::getFields
1776 * CommentStore::getJoin
1777 * CommentStore::getComment
1778 * CommentStore::getCommentLegacy
1779 * CommentStore::insert
1780 * CommentStore::insertWithTemplate
1781 * The following methods in Title have been renamed, and the old ones are
1782 deprecated:
1783 * Title::getSkinFromCssJsSubpage – use ::getSkinFromConfigSubpage
1784 * Title::isCssOrJsPage – use ::isSiteConfigPage
1785 * Title::isCssJsSubpage – use ::isUserConfigPage
1786 * Title::isCssSubpage – use ::isUserCssConfigPage
1787 * Title::isJsSubpage – use ::isUserJsConfigPage
1788 * The following methods related to caching of half-parsed HTML were deprecated:
1789 * Parser::serializeHalfParsedText()
1790 * Parser::unserializeHalfParsedText()
1791 * Parser::isValidHalfParsedText()
1792 * StripState::getSubState()
1793 * StripState::merge()
1794 * The DeferredStringifier class is deprecated, use Message::listParam() instead.
1795 * The type string for the parameter $lang of DateFormatter::getInstance is
1796 deprecated.
1797 * Wikimedia\Rdbms\SavepointPostgres is deprecated.
1798 * The DO_MAINTENANCE constant is deprecated. RUN_MAINTENANCE_IF_MAIN should be
1799 used instead.
1800 * The function wfShellWikiCmd() has been deprecated, use
1801 MediaWiki\Shell::makeScriptCommand().
1802 * In the future, the hooks 'PreferencesFormPreSave' and 'PreferencesGetLegend'
1803 will be allowed to provide any HTMLForm object rather than PreferencesForm.
1804
1805 === Other changes in 1.31 ===
1806 * Browser support for Internet Explorer 10 was lowered from Grade A to Grade C.
1807 * Browser support for Opera 12 and older was dropped entirely. Opera 15+
1808 continues at Grade A.
1809 * Multi-content-revision capability was introduced into the storage layer. See
1810 <https://mediawiki.org/wiki/Requests_for_comment/Multi-Content_Revisions>.
1811 * The "free" CSS class is now only applied to unbracketed URLs in wikitext.
1812 Links written using square brackets will get the class "text" not "free".
1813 * RFC 157418: Whitespace is trimmed from wikitext headings, wikitext list items,
1814 wikitext table captions, wikitext table headings, wikitext table cells. HTML
1815 headings, HTML list items, HTML table captions, HTML table headings, HTML
1816 table cells will not have this trimming behavior.
1817
1818 == Compatibility ==
1819 MediaWiki 1.31 requires PHP 7.0.0 or later. Although HHVM 3.18.5 or later is
1820 supported, it is generally advised to use PHP 7.0.0 or later for long term
1821 support.
1822
1823 MySQL/MariaDB is the recommended DBMS. PostgreSQL or SQLite can also be used,
1824 but support for them is somewhat less mature. There is experimental support for
1825 Oracle and Microsoft SQL Server.
1826
1827 The supported versions are:
1828
1829 * MySQL 5.5.8 or later
1830 * PostgreSQL 9.2 or later
1831 * SQLite 3.3.7 or later
1832 * Oracle 9.0.1 or later
1833 * Microsoft SQL Server 2005 (9.00.1399)
1834
1835 == Upgrading ==
1836 1.31 has several database changes since 1.30, and will not work without schema
1837 updates. Note that due to changes to some very large tables like the revision
1838 table, the schema update may take quite long (minutes on a medium sized site,
1839 many hours on a large site).
1840
1841 Don't forget to always back up your database before upgrading!
1842
1843 See the file UPGRADE for more detailed upgrade instructions, including
1844 important information when upgrading from versions prior to 1.11.
1845
1846 For notes on 1.30.x and older releases, see HISTORY.
1847
1848 == Online documentation ==
1849 Documentation for both end-users and site administrators is available on
1850 MediaWiki.org, and is covered under the GNU Free Documentation License (except
1851 for pages that explicitly state that their contents are in the public domain):
1852
1853 https://www.mediawiki.org/wiki/Special:MyLanguage/Documentation
1854
1855 == Mailing list ==
1856 A mailing list is available for MediaWiki user support and discussion:
1857
1858 https://lists.wikimedia.org/mailman/listinfo/mediawiki-l
1859
1860 A low-traffic announcements-only list is also available:
1861
1862 https://lists.wikimedia.org/mailman/listinfo/mediawiki-announce
1863
1864 It's highly recommended that you sign up for one of these lists if you're
1865 going to run a public MediaWiki, so you can be notified of security fixes.
1866
1867 == IRC help ==
1868 There's usually someone online in #mediawiki on irc.freenode.net.
1869
1870
1871 = MediaWiki 1.30 =
1872
1873 == MediaWiki 1.30.2 ==
1874
1875 This is a security and maintenance release of the MediaWiki 1.30 branch.
1876
1877 === Changes since MediaWiki 1.30.1 ===
1878 * (T204729) WatchedItemStore::countVisitingWatchersMultiple() shouldn't query
1879 all titles when asked for none.
1880 * (T109121) Remove deprecated pear/mail_mime-decode from composer suggested
1881 libraries.
1882 * (T207540) Include IP address in "Login for $1 succeeded" log entry.
1883 * (T205765) Don't link to the obsolete "Extension Matrix" page in installer.
1884 * (T207603) SECURITY: User JS may no longer be loaded with mime type
1885 text/javascript if there is no account associated with the username.
1886 * (T113042) SECURITY: Do not allow loading pages raw with a text/javascript MIME
1887 type if non-admins can edit the page.
1888 * (T207541) Pass email address to mail().
1889 * Fix addition of ug_expiry column to user_groups table on MSSQL.
1890 * (T204531) rdbms: reduce LoadBalancer replication log spam.
1891 * (T213489) Avoid session double-start in Setup.php.
1892 * (T195525) Fix db error outage page.
1893 * (T208871) The hard-coded Google search form on the database error page was
1894 removed.
1895 * (T216968) Return pageid as int in both list=iwbacklinks and
1896 list=langbacklinks.
1897 * (T218608) SECURITY: Fix an issue that prevents Extension:OAuth working when
1898 $wgBlockDisablesLogin is true.
1899 * (T25227) SECURITY: action=logout now requires to be posted and have a csrf
1900 token.
1901 * (T222385) resourceloader: Use AND instead of OR for upsert conds in
1902 saveFileDependencies().
1903 * (T224374) Fix message parameters so that the message that says SQLite is out
1904 of date makes sense.
1905 * SpecialPage::checkLoginSecurityLevel() will now preserve POST data when
1906 reauthenticating.
1907 * FormSpecialPage::execute() will now call checkLoginSecurityLevel() if
1908 getLoginSecurityLevel() returns non-false.
1909 * (T197279) SECURITY: Fix reauth in Special:ChangeEmail.
1910 * (T208881) SECURITY: blacklist CSS var().
1911 * (T209794) SECURITY: rate-limit and prevent blocked users from changing email.
1912 * (T199540) SECURITY: API: Respect $wgBlockCIDRLimit in action=block.
1913 * (T212118) SECURITY: Fix cache mode for (un)patrolled recent changes query.
1914 * (T222036, T222038) SECURITY: Add permission check for user is permitted to
1915 view the log type.
1916 * (T221739) SECURITY: resources: Patch jQuery 1.11.3 for CVE-2019-11358.
1917
1918 == MediaWiki 1.30.1 ==
1919
1920 This is a security and maintenance release of the MediaWiki 1.30 branch.
1921
1922 === Changes since MediaWiki 1.30.0 ===
1923 * (T169545, CVE-2018-0503) SECURITY: $wgRateLimits entry for 'user' overrides
1924 'newbie'.
1925 * (T194605, CVE-2018-0505) SECURITY: BotPasswords can bypass CentralAuth's
1926 account lock.
1927 * (T87572) Make FormatMetadata::flattenArrayReal() work for an associative
1928 array.
1929 * Updated composer/spdx-licenses from 1.1.4 to 1.3.0 (development dependency).
1930 * (T189567) the CLI installer (maintenance/install.php) learned to detect and
1931 include extensions. Pass --with-extensions to enable that feature.
1932 * (T190503) Let built-in web server (maintenance/dev) handle .php requests.
1933 * (T167507) selenium: Run Chrome headlessly.
1934 * selenium: Pass -no-sandbox to Chrome under Docker.
1935 * (T179190) selenium: Move logic for running tests from package.json to
1936 selenium.sh
1937 * (T192584) Stop incorrectly passing USE INDEX to RecentChange::newFromConds().
1938 * Add default edit rate limit of 90 edits/minute for all users.
1939 * (T186565) Fix PHP Notice from `ob_end_flush()` in `FileRepo::streamFile()`.
1940 * oojs/oojs-ui updated to remove an unnecessary dependancy.
1941 * (T196125) php-memcached 3.0 (provided with PHP 7.0) is now supported.
1942 * (T118683) Fix exception from &$user deref on HHVM in the TitleMoveComplete
1943 hook.
1944 * (T196672) The mtime of extension.json files is now able to be zero
1945 * (T180403) Validate $length in padleft/padright parser functions.
1946 * (T143790) Make $wgEmailConfirmToEdit only affect edit actions.
1947 * (T193995) Fix undefined patchPath() method call in parser tests.
1948 * Special:BotPasswords now requires reauthentication.
1949 * (T191608, T187638) Add 'logid' parameter to Special:Log.
1950 * (T193829) Indicate when a Bot Password needs reset.
1951 * (T151415) Log email changes.
1952 * (T200861) Fix total breakage of SQLite web upgrade.
1953 * (T202550) Unbreak SpecialListusersHeaderForm and SpecialListusersHeader
1954 hooks.
1955 * (T190539) Explicitly require Postgres 9.1.
1956 * (T118420) Unbreak Oracle installer.
1957
1958 == MediaWiki 1.30.0 ==
1959
1960 === Changes since MediaWiki 1.30.0-rc.0 ===
1961 * Upgraded Moment.js from v2.15.0 to v2.19.3.
1962 * Add ip_changes to postgres/tables.sql.
1963 * Skip null shell parameters.
1964 * Add wfWaitForSlaves() to maintenance/migrateComments.php.
1965 * (T182245) Fix join conditions in ImageListPager.
1966 * (T178626) Revert #contentSub and #jump-to-nav margin changes.
1967
1968 === MySQL version requirement in 1.30 ===
1969 As of 1.30, MediaWiki now requires MySQL 5.5.8 or higher (see Compatibility
1970 section).
1971
1972 === Configuration changes in 1.30 ===
1973 * The "C.UTF-8" locale should be used for $wgShellLocale, if available, to avoid
1974 unexpected behavior when code uses locale-sensitive string comparisons. For
1975 example, the Scribunto extension considers "bar" < "Foo" in most locales
1976 since it ignores case.
1977 * $wgShellLocale now affects LC_ALL rather than only LC_CTYPE. See
1978 documentation of $wgShellLocale for details.
1979 * $wgShellLocale is now applied for all requests. wfInitShellLocale() is
1980 deprecated and a no-op, as it is no longer needed.
1981 * $wgJobClasses may now specify callback functions as an alternative to plain
1982 class names. This is intended for extensions that want control over the
1983 instantiation of their jobs, to allow for proper dependency injection.
1984 * $wgResourceModules may now specify callback functions as an alternative
1985 to plain class names, using the 'factory' key in the module description
1986 array. This allows dependency injection to be used for ResourceLoader modules.
1987 * $wgExceptionHooks has been removed.
1988 * (T163562) $wgRangeContributionsCIDRLimit was introduced to control the size
1989 of IP ranges that can be queried at Special:Contributions.
1990 * (T45547) $wgUsePigLatinVariant added (off by default).
1991 * (T152540) MediaWiki now supports a section ID escaping style that allows to
1992 display non-Latin characters verbatim on many modern browsers. This is
1993 controlled by the new configuration setting, $wgFragmentMode.
1994 * $wgExperimentalHtmlIds is now deprecated and will be removed in a future
1995 version, use $wgFragmentMode to migrate off it to a modern alternative.
1996 * $wgExternalInterwikiFragmentMode was introduced to control how fragments in
1997 sinterwikis going outside of current wiki farm are encoded.
1998 * (T120333) Soft-deprecated the use of PHP extension 'mysql' in favor of
1999 'mysqli'. This PHP extension was deprecated in PHP 5.5 and removed in PHP 7.0.
2000 MediaWiki auto-selects the 'mysqli' driver since MediaWiki 1.22, except if
2001 explicitly requested through the configuration parameter $wgDBservers.
2002 * $wgOOUIEditPage was removed, as it is now the default. This was documented as
2003 a temporary variable during the migration period.
2004
2005 === New features in 1.30 ===
2006 * (T37247) Output from Parser::parse() will now be wrapped in a div with
2007 class="mw-parser-output" by default. This may be changed or disabled using
2008 ParserOptions::setWrapOutputClass().
2009 * (T163562) Added ability to search for contributions within an IP ranges
2010 at Special:Contributions.
2011 * Added 'ChangeTagsAllowedAdd' hook, enabling extensions to allow software-
2012 specific tags to be added by users.
2013 * Added a 'ParserOptionsRegister' hook to allow extensions to register
2014 additional parser options.
2015 * (T45547) Included Pig Latin, a language game in English, as a
2016 LanguageConverter variant. This allows English-speaking developers
2017 to develop and test LanguageConverter more easily. Pig Latin can be
2018 enabled by setting $wgUsePigLatinVariant to true.
2019 * Added RecentChangesPurgeRows hook to allow extensions to purge data that
2020 depends on the recentchanges table.
2021 * Added JS config values wgDiffOldId/wgDiffNewId to the output of diff pages.
2022 * (T2424) Added direct unwatch links to entries in Special:Watchlist (if the
2023 'watchlistunwatchlinks' preference option is enabled). With JavaScript
2024 enabled, these links toggle so the user can also re-watch pages that have
2025 just been unwatched.
2026 * Added $wgParserTestMediaHandlers, where mock media handlers can be passed to
2027 MediaHandlerFactory for parser tests.
2028 * Edit summaries, block reasons, and other "comments" are now stored in a
2029 separate database table. Use the CommentFormatter class to access them.
2030 ** This is currently gated by $wgCommentTableSchemaMigrationStage. Most wikis
2031 can set this to MIGRATION_NEW and run maintenance/migrateComments.php as
2032 soon as any necessary extensions are updated.
2033 * (T138166) Added ability for users to prohibit other users from sending them
2034 emails with Special:Emailuser. Can be enabled by setting
2035 $wgEnableUserEmailBlacklist to true.
2036 * (T67297) $wgBrowserBlacklist is deprecated, and changing it will have no
2037 effect. Instead, users using browsers that do not support Unicode will be
2038 unable to edit and should upgrade to a modern browser instead.
2039
2040 === External library changes in 1.30 ===
2041
2042 ==== Upgraded external libraries ====
2043 * Updated justinrainbow/json-schema from v3.0 to v5.2.
2044 * Updated mediawiki/mediawiki-codesniffer from v0.7.2 to v0.12.0.
2045 * Updated wikimedia/composer-merge-plugin from v1.4.0 to v1.4.1.
2046 * Updated wikimedia/relpath from v1.0.3 to v2.0.0.
2047 * Updated OOjs from v2.0.0 to v2.1.0.
2048 * Updated OOUI from v0.21.1 to v0.23.0.
2049 * Updated QUnit from v1.23.1 to v2.4.0.
2050 * Updated phpunit/phpunit from v4.8.35 to v4.8.36.
2051 * Upgraded Moment.js from v2.15.0 to v2.19.3.
2052
2053 ==== New external libraries ====
2054 * The class \TestingAccessWrapper has been moved to the external library
2055 wikimedia/testing-access-wrapper and renamed \Wikimedia\TestingAccessWrapper.
2056 * Purtle, a fast, lightweight RDF generator.
2057
2058 ==== Removed and replaced external libraries ====
2059 * …
2060
2061 === Bug fixes in 1.30 ===
2062 * (T151633) Ordered list items use now Devanagari digits in Nepalese
2063 (thanks to Sfic)
2064
2065 === Action API changes in 1.30 ===
2066 * (T37247) action=parse output will be wrapped in a div with
2067 class="mw-parser-output" by default. This may be changed or disabled using
2068 the new 'wrapoutputclass' parameter.
2069 * When errorformat is not 'bc', abort reasons from action=login will be
2070 formatted as specified by the error formatter parameters.
2071 * action=compare can now handle arbitrary text, deleted revisions, and
2072 returning users and edit comments.
2073 * (T164106) The 'rvdifftotext', 'rvdifftotextpst', 'rvdiffto',
2074 'rvexpandtemplates', 'rvgeneratexml', 'rvparse', and 'rvprop=parsetree'
2075 parameters to prop=revisions are deprecated, as are the similarly named
2076 parameters to prop=deletedrevisions, list=allrevisions, and
2077 list=alldeletedrevisions. Use action=compare, action=parse, or
2078 action=expandtemplates instead.
2079
2080 === Action API internal changes in 1.30 ===
2081 * ApiBase::getDescriptionMessage() and the "apihelp-*-description" messages are
2082 deprecated. The existing message should be split between "apihelp-*-summary"
2083 and "apihelp-*-extended-description".
2084 * (T123931) Individual values of multi-valued parameters can now be marked as
2085 deprecated.
2086
2087 === Languages updated in 1.30 ===
2088 MediaWiki supports over 350 languages. Many localisations are updated
2089 regularly. Below only new and removed languages are listed, as well as
2090 changes to languages because of Phabricator reports.
2091
2092 * Added: kbp (Kabɩyɛ / Kabiyè)
2093 * Added: skr (Saraiki, سرائیکی)
2094 * Added: tay (Tayal / Atayal)
2095 * Removed: tokipona (Toki Pona)
2096
2097 ==== Pig Latin added ====
2098 * (T45547) Added Pig Latin, a made-up English variant (en-x-piglatin),
2099 for easier variant development and testing. Disabled by default. It can be
2100 enabled by setting $wgUsePigLatinVariant to true.
2101
2102 === Other changes in 1.30 ===
2103 * The use of an associative array for $wgProxyList, where the IP address is in
2104 the key instead of the value, is deprecated (e.g. [ '127.0.0.1' => 'value' ]).
2105 Please convert these arrays to indexed/sequential ones (e.g. [ '127.0.0.1' ]).
2106 * mw.user.bucket (deprecated in 1.23) was removed.
2107 * LoadBalancer::getServerInfo() and LoadBalancer::setServerInfo() are
2108 deprecated. There are no known callers.
2109 * File::getStreamHeaders() was deprecated.
2110 * MediaHandler::getStreamHeaders() was deprecated.
2111 * Title::canTalk() was deprecated. The new Title::canHaveTalkPage() should be
2112 used instead.
2113 * MWNamespace::canTalk() was deprecated. The new MWNamespace::hasTalkNamespace()
2114 should be used instead.
2115 * The ExtractThumbParameters hook (deprecated in 1.21) was removed.
2116 * The OutputPage::addParserOutputNoText and ::getHeadLinks methods (both
2117 deprecated in 1.24) were removed.
2118 * wfMemcKey() and wfGlobalCacheKey() were deprecated. BagOStuff::makeKey() and
2119 BagOStuff::makeGlobalKey() should be used instead.
2120 * (T146304) Preprocessor handling of LanguageConverter markup has been improved.
2121 As a result of the new uniform handling, '-{' may need to be escaped
2122 (for example, as '-<nowiki/>{') where it occurs inside template arguments
2123 or wikilinks.
2124 * (T163966) Page moves are now counted as edits for the purposes of
2125 autopromotion, i.e., they increment the user_editcount field in the database.
2126 * Two new hooks, LogEventsListLineEnding and NewPagesLineEnding, were added for
2127 manipulating Special:Log and Special:NewPages lines.
2128 * The OldChangesListRecentChangesLine, EnhancedChangesListModifyLineData,
2129 PageHistoryLineEnding, ContributionsLineEnding and
2130 DeletedContributionsLineEnding hooks have an additional parameter, for
2131 manipulating HTML data attributes of RC/history lines.
2132 EnhancedChangesListModifyBlockLineData can do that via the
2133 $data['attribs'] subarray.
2134 * (T130632) The OutputPage::enableTOC() method was removed.
2135 * WikiPage::getParserOutput() will now throw an exception if passed
2136 ParserOptions that would pollute the parser cache. Callers should use
2137 WikiPage::makeParserOptions() to create the ParserOptions object and only
2138 change options that affect the parser cache key.
2139 * Article::viewRedirect() is deprecated.
2140 * IP::isValidBlock() was deprecated. Use the equivalent IP::isValidRange().
2141 * DeprecatedGlobal no longer supports passing in a direct value, it requires a
2142 callable factory function or a class name.
2143 * The $parserMemc global, wfGetParserCacheStorage(), and
2144 ParserCache::singleton() are all deprecated. The main ParserCache instance
2145 should be obtained from MediaWikiServices instead. Access to the underlying
2146 BagOStuff is possible through the new ParserCache::getCacheStorage() method.
2147 * .mw-ui-constructive CSS class (deprecated in 1.27) was removed.
2148 * Sanitizer::escapeId() was deprecated, use escapeIdForAttribute(),
2149 escapeIdForLink() or escapeIdForExternalInterwiki() instead.
2150 * Title::escapeFragmentForURL() was deprecated, use one of the aforementioned
2151 Sanitizer functions or, if possible, Title::getFragmentForURL().
2152 * Second parameter to Sanitizer::escapeIdReferenceList() ($options) now does
2153 nothing and is deprecated.
2154 * mw.util.escapeId() was deprecated, use escapeIdForAttribute() or
2155 escapeIdForLink().
2156 * MagicWord::replaceMultiple() (deprecated in 1.25) was removed.
2157 * WikiImporter now requires the second parameter to be an instance of the
2158 Config, class. Prior to that, the Config parameter was optional (a behavior
2159 deprecated in 1.25).
2160 * Removed 'jquery.mwExtension' module. (deprecated since 1.26)
2161 * mediawiki.ui: Deprecate greys, which are not part of WikimediaUI color palette
2162 any more.
2163 * CdbReader, CdbWriter, CdbException classes (deprecated in 1.25) were removed.
2164 The namespaced classes in the Cdb namespace should be used instead.
2165 * IPSet class (deprecated in 1.26) was removed. The namespaced IPSet\IPSet
2166 should be used instead.
2167 * RunningStat class (deprecated in 1.27) was removed. The namespaced
2168 RunningStat\RunningStat should be used instead.
2169 * MWMemcached and MemCachedClientforWiki classes (deprecated in 1.27) were
2170 removed.
2171 The MemcachedClient class should be used instead.
2172 * EditPage underwent some refactoring and deprecations:
2173 * EditPage::isOouiEnabled() is deprecated and will always return true.
2174 * EditPage::getSummaryInput() and ::getSummaryInputOOUI() are deprecated.
2175 Please use ::getSummaryInputWidget() instead.
2176 * EditPage::getCheckboxes() and ::getCheckboxesOOUI() are deprecated. Please
2177 use ::getCheckboxesWidget() instead.
2178 * Creating an EditPage instance without calling EditPage::setContextTitle()
2179 should be avoided and will be deprecated in a future release.
2180 * EditPage::safeUnicodeInput() and ::safeUnicodeOutput() are deprecated and
2181 no-ops.
2182 * EditPage::$isCssJsSubpage, ::$isCssSubpage, and ::$isJsSubpage are
2183 deprecated. The corresponding methods from Title should be used instead.
2184 * EditPage::$isWrongCaseCssJsPage is deprecated. There is no replacement.
2185 * EditPage::$mArticle and ::$mTitle are deprecated for public usage. The
2186 getters ::getArticle() and ::getTitle() should be used instead.
2187 * Trying to control or fake EditPage context by overriding $wgUser,
2188 $wgRequest, $wgOut, and $wgLang is no longer supported and won't work. The
2189 IContextSource returned from EditPage::getContext() must be modified
2190 instead.
2191 * Parser::getRandomString() (deprecated in 1.26) was removed.
2192 * Parser::uniqPrefix() (deprecated in 1.26) was removed.
2193 * Parser::extractTagsAndParams() now only accepts three arguments. The fourth,
2194 $uniq_prefix was deprecated in 1.26 and has now been removed.
2195 * (T172514) The following tables have had their UNIQUE indexes turned into
2196 proper PRIMARY KEYs for increased maintainability: categorylinks, imagelinks,
2197 iwlinks, langlinks, log_search, module_deps, objectcache, pagelinks,
2198 query_cache, site_stats, templatelinks, text, transcache, user_former_groups,
2199 user_properties.
2200 * IDatabase::nextSequenceValue() is no longer needed by any database backends
2201 (formerly it was needed by PostgreSQL and Oracle), and is now deprecated.
2202 * (T146591) The lc_lang_key index on the l10n_cache table has been changed into
2203 a PRIMARY KEY.
2204 * (T157227) bot_password.bp_user, change_tag.ct_log_id, change_tag.ct_rev_id,
2205 page_restrictions.pr_user, tag_summary.ts_log_id, tag_summary.ts_rev_id and
2206 user_properties.up_user have all been made unsigned on MySQL.
2207 * DB_SLAVE is deprecated. DB_REPLICA should be used instead.
2208 * wfUsePHP() is deprecated.
2209 * wfFixSessionID() was removed.
2210 * wfShellExec() and related functions are deprecated, use Shell::command(). This
2211 also slightly changes the behavior of how execution time limits are calculated
2212 when only some of defaults are overridden per-call. When in doubt, always
2213 override both wall clock and CPU time.
2214 * (T138166) SpecialEmailUser::getTarget() now requires a second argument, the
2215 sending user object. Using the method without the second argument is
2216 deprecated.
2217 * (T67297) Browsers that don't support Unicode will have their edits rejected.
2218 * (T178450) The module 'jquery.badge' is deprecated and will be removed in a
2219 future release. For notifying the user of an event, the Notifications ("Echo")
2220 system should be used instead.
2221 * (T178451) SECURITY: Potential XSS when $wgShowExceptionDetails = false and
2222 browser sends non-standard url escaping.
2223 * (T165846) SECURITY: BotPassword login attempts weren't throttled.
2224
2225 = MediaWiki 1.29 =
2226
2227 == MediaWiki 1.29.3 ==
2228
2229 This is a security and maintenance release of the MediaWiki 1.29 branch.
2230
2231 === Changes since 1.29.2 ===
2232 * (T169545, CVE-2018-0503) SECURITY: $wgRateLimits entry for 'user' overrides
2233 'newbie'.
2234 * (T194605, CVE-2018-0505) SECURITY: BotPasswords can bypass CentralAuth's
2235 account lock.
2236 * (T180551) Fix LanguageSrTest for language converter
2237 * (T180552) Fix language converter parser test with self-close tags
2238 * (T180537) Remove $wgAuth usage from wrapOldPasswords.php
2239 * (T180485) InputBox: Have inputbox langconvert certain attributes
2240 * (T161732, T181547) Upgraded Moment.js from v2.15.0 to v2.19.3.
2241 * (T172927) Drop vendor from MW release branch
2242 * (T87572) Make FormatMetadata::flattenArrayReal() work for an associative array
2243 * Updated composer/spdx-licenses from 1.1.4 to 1.3.0 (development dependency).
2244 * (T189567) the CLI installer (maintenance/install.php) learned to detect and
2245 include extensions. Pass --with-extensions to enable that feature.
2246 * (T182381) Mask deprecated call in WatchedItemUnitTest
2247 * (T190503) Let built-in web server (maintenance/dev) handle .php requests.
2248 * The karma qunit tests would fail on some configuration due to headers already
2249 sent. Check headers_sent() before sending cpPosTime headers
2250 * (T167507) selenium: Run Chrome headlessly.
2251 * selenium: Pass -no-sandbox to Chrome under Docker
2252 * (T191247) Use MediaWiki\SuppressWarnings around trigger_error('') instead @
2253 * (T75174, T161041) Unit test ChangesListSpecialPageTest::testFilterUserExpLevel
2254 fails under SQLite.
2255 * (T192584) Stop incorrectly passing USE INDEX to RecentChange::newFromConds().
2256 * (T179190) selenium: Move test running logic from package.json to selenium.sh.
2257 * (T117839, T193200) PDFHandler: Fix for pdfinfo changes in poppler-utils 0.48.
2258 * Add default edit rate limit of 90 edits/minute for all users.
2259 * (T196125) php-memcached 3.0 (provided with PHP 7.0) is now supported.
2260 * (T196672) The mtime of extension.json files is now able to be zero
2261 * (T180403) Validate $length in padleft/padright parser functions.
2262 * (T143790) Make $wgEmailConfirmToEdit only affect edit actions.
2263 * (T194237) Special:BotPasswords now requires reauthentication.
2264 * (T191608, T187638) Add 'logid' parameter to Special:Log.
2265 * (T176097) resourceloader: Disable a flaky MessageBlobStoreTest case
2266 * (T193829) Indicate when a Bot Password needs reset.
2267 * (T151415) Log email changes.
2268 * (T118420) Unbreak Oracle installer.
2269
2270 == MediaWiki 1.29.2 ==
2271
2272 This is a security and maintenance release of the MediaWiki 1.29 branch.
2273
2274 === Changes since 1.29.1 ===
2275 * (T166757) Avoid scoped lock errors in Category::refreshCounts() due to
2276 nesting.
2277 * (T175439) Unbreak Postgres Updater when setting defaults for a column.
2278 * (T160298) Remove use of implicitGroupBy() in ActiveUsersPager.
2279 * Fixed login button label to accept RawMessage.
2280 * Fixed case of SpecialRecentChanges class usage.
2281 * (T174255) Declare uploadCount property in importDump.php.
2282 * (T163646) Pass a string not an int to mysql_real_escape_string().
2283 * (T180143) Bump justinrainbow/json-schema development dependency to ~5.2.
2284 * Updated dev dependancy phpunit/phpunit from v4.8.35 to v4.8.36.
2285 * (T178451) SECURITY: Potential XSS when $wgShowExceptionDetails = false and
2286 browser sends non-standard url escaping.
2287 * (T165846) SECURITY: BotPassword login attempts weren't throttled.
2288 * (T128209) SECURITY: Reflected File Download from api.php.
2289 * (T134100) SECURITY: Do not reveal if user exists during login failure.
2290 * (T176247) SECURITY: Ensure Message::rawParams can't lead to XSS.
2291 * (T125163) SECURITY: Make anchor for headlines escape > and <.
2292 * (T180237) SECURITY: Protect vendor folder with .htaccess.
2293 * (T180231) SECURITY: Remove PHPUnit file with known RCE if exists in
2294 update.php.
2295 * (T124404) SECURITY: XSS in langconverter when regex hits pcre.backtrack_limit.
2296 * (T119158) SECURITY: Handle -{}- syntax in attributes safely.
2297 * (T180488) (T125177) "api.log contains passwords in plaintext" wasn't correctly
2298 fixed in all branches in the previous security release.
2299
2300 == MediaWiki 1.29.1 ==
2301
2302 This is a maintenance release of the MediaWiki 1.29 branch.
2303
2304 The SpamBlacklist and PdfHandler extensions were missing from the generated
2305 packages.
2306
2307 === Changes since 1.29.1 ===
2308 * (T164999) Define mw.Upload.Dialog.static.name in mediawiki.Upload.Dialog.js.
2309 * (T172061) Fix fatal when passing a category to refreshLinks.php.
2310
2311 == MediaWiki 1.29.0 ==
2312
2313 === Configuration changes in 1.29 ===
2314 * Default cookie expiration time has been reduced to 30 days. Login cookie
2315 expiration time is kept at 180 days.
2316 * A new configuration variable has been added: $wgCookieSetOnAutoblock. This
2317 determines whether to set a cookie when a user is autoblocked. Doing so means
2318 that a blocked user, even after logging out and moving to a new IP address,
2319 will still be blocked.
2320 * The resetpassword right and associated password reset capture feature has
2321 been removed.
2322 * The $error parameter to the EmailUser hook should be set to a Status object
2323 or boolean false. This should be compatible with at least MediaWiki 1.23 if
2324 not earlier. Returning a raw HTML string is now deprecated.
2325 * The $message parameter to the ApiCheckCanExecute hook should be set to an
2326 ApiMessage. This is compatible with MediaWiki 1.27 and later. Returning a
2327 code for ApiBase::parseMsg() will no longer work.
2328 * ApiBase::$messageMap is no longer public. Code attempting to access it will
2329 result in a PHP fatal error.
2330 * $wgUserEmailUseReplyTo is now true by default to work around restrictive DMARC
2331 policies.
2332 * Subpages are now enabled by default in the Template namespace. Set
2333 $wgNamespacesWithSubpages[NS_TEMPLATE] to false to keep the old behavior.
2334 * $wgRunJobsAsync is now false by default (T142751). This change only affects
2335 wikis with $wgJobRunRate > 0.
2336 * (T158474) "Unknown user" has been added to $wgReservedUsernames.
2337 * (T156983) $wgRateLimitsExcludedIPs now accepts CIDR ranges as well as single
2338 IPs.
2339 * $wgDummyLanguageCodes is deprecated. Additional language code mappings may be
2340 added to $wgExtraLanguageCodes instead.
2341 * (T161453) LocalisationCache will no longer use the temporary directory in it's
2342 fallback chain when trying to work out where to write the cache.
2343 * The user right 'editusercssjs' (deprecated in 1.16) was removed. Use
2344 'editusercss' and 'edituserjs' in $wgGroupPermissions and elsewhere instead.
2345
2346 === New features in 1.29 ===
2347 * (T5233) A cookie can now be set when a user is autoblocked, to track that user
2348 if they move to a new IP address. This is disabled by default.
2349 * Added ILocalizedException interface to standardize the use of localized
2350 exceptions, largely so the API can handle them more sensibly.
2351 * Blocks created automatically by MediaWiki, such as for configured proxies or
2352 dnsbls, are now indicated as such and use a new i18n message when displayed.
2353 * Added new $wgHTTPImportTimeout setting. Sets timeout for
2354 downloading the XML dump during a transwiki import in seconds.
2355 * Parser limit report is now available in machine-readable format to JavaScript
2356 via mw.config.get('wgPageParseReport').
2357 * Added $wgSoftBlockRanges, to allow for automatically blocking anonymous edits
2358 from certain IP ranges (e.g. private IPs).
2359 * (T59603) Added new magic word {{PAGELANGUAGE}} which returns the language code
2360 of the page being parsed.
2361 * HTML5 form validation attributes will no longer be suppressed. Originally
2362 browsers had poor support for them, but modern browsers handle them fine.
2363 This might affect some forms that used them and only worked because the
2364 attributes were not actually being set.
2365 * Expiry times can now be specified when users are added to user groups.
2366 * Completely new user interface for the RecentChanges page, which
2367 structures filters into user-friendly groups. This has corresponding
2368 changes to how filters are registered by core and extensions.
2369 * The edit form now uses pretty OOjs UI buttons, checkboxes and summary input.
2370 Because this change can cause problems for extensions and on-wiki
2371 scripts depending on the exact HTML, the old version is still available
2372 and can be used by setting $wgOOUIEditPage = false; in LocalSettings.php.
2373 This will be removed later and OOjs UI will become the only option.
2374 To make testing easier, users can also force either mode by adding
2375 &ooui=true or &ooui=false to the action=edit URL.
2376
2377 === External library changes in 1.29 ===
2378
2379 ==== Upgraded external libraries ====
2380 * Updated QUnit from v1.22.0 to v1.23.1.
2381 * Updated cssjanus from v1.1.2 to v1.2.0.
2382 * Updated psr/log from v1.0.0 to v1.0.2.
2383 * Update Moment.js from v2.8.4 to v2.15.0.
2384 * Updated oyejorge/less.php from v1.7.0.10 to v1.7.0.14.
2385 * Updated monolog from v1.18.2 to 1.22.1.
2386 * Updated wikimedia/composer-merge-plugin from v1.3.1 to v1.4.0.
2387 * Updated OOjs from v1.1.10 to v2.0.0.
2388 * Updated jQuery from v1.11.3 to v3.2.1 (including jQuery Migrate v3.0.0).
2389
2390 ==== New external libraries ====
2391 * Added wikimedia/timestamp v1.0.0.
2392 * Added wikimedia/remex-html v1.0.1.
2393
2394 ==== Removed and replaced external libraries ====
2395
2396 === Bug fixes in 1.29 ===
2397 * (T62604) Core parser functions returning a number now format the number
2398 according to the page content language, not wiki content language.
2399 * (T27187) Search suggestions based on jquery.suggestions will now correctly
2400 only highlight prefix matches in the results.
2401 * (T157035) "new mw.Uri()" was ignoring options when using default URI.
2402 * Special:Allpages can no longer be filtered by redirect in miser mode.
2403 * (T160519) CACHE_ANYTHING will not be CACHE_ACCEL if no accelerator is
2404 installed.
2405 * (T109140) (T122209) SECURITY: Special:UserLogin and Special:Search allow
2406 redirect to interwiki links.
2407 * (T144845) SECURITY: XSS in SearchHighlighter::highlightText() when
2408 $wgAdvancedSearchHighlighting is true.
2409 * (T125177) SECURITY: API parameters may now be marked as "sensitive" to keep
2410 their values out of the logs.
2411 * (T150044) SECURITY: "Mark all pages visited" on the watchlist now requires a
2412 CSRF token.
2413 * (T156184) SECURITY: Escape content model/format url parameter in message.
2414 * (T151735) SECURITY: SVG filter evasion using default attribute values in DTD
2415 declaration.
2416 * (T161453) SECURITY: LocalisationCache will no longer use the temporary
2417 directory in it's fallback chain when trying to work out where to write the
2418 cache.
2419 * (T48143) SECURITY: Spam blacklist ineffective on encoded URLs inside file
2420 inclusion syntax's link parameter.
2421 * (T108138) SECURITY: Sysops can undelete pages, although the page is protected
2422 against it.
2423
2424 === Action API changes in 1.29 ===
2425 * Submitting sensitive authentication request parameters to action=login,
2426 action=clientlogin, action=createaccount, action=linkaccount, and
2427 action=changeauthenticationdata in the query string is now an error. They
2428 should be submitted in the POST body instead.
2429 * The capture option for action=resetpassword has been removed
2430 * action=clearhasmsg now requires a POST.
2431 * (T47843) API errors and warnings may be requested in non-English languages
2432 using the new 'errorformat', 'errorlang', and 'errorsuselocal' parameters.
2433 * API error codes may have changed. Most notably, errors from modules using
2434 parameter prefixes (e.g. all query submodules) will no longer be prefixed.
2435 * ApiPageSet-using modules will report the 'invalidreason' using the specified
2436 'errorformat'.
2437 * action=emailuser may return a "Warnings" status, and now returns 'warnings'
2438 and 'errors' subelements (as applicable) instead of 'message'.
2439 * action=imagerotate returns an 'errors' subelement rather than 'errormessage'.
2440 * action=move now reports errors when moving the talk page as an array under
2441 key 'talkmove-errors', rather than using 'talkmove-error-code' and
2442 'talkmove-error-info'. The format for subpage move errors has also changed.
2443 * action=revisiondelete no longer includes a "rendered" property on warnings
2444 and errors for each item. Use errorformat=wikitext if you're wanting parsed
2445 output.
2446 * action=rollback no longer returns a "messageHtml" property. Use
2447 errorformat=html if you're wanting HTML formatting of error messages.
2448 * action=upload now reports optional stash failures as an array under key
2449 'stasherrors' rather than a 'stashfailed' text string.
2450 * action=watch reports 'errors' and 'warnings' instead of a single 'error', and
2451 no longer returns a 'message' on success.
2452 * Added action=validatepassword to validate passwords for the account creation
2453 and password change forms.
2454 * action=purge now requires a POST.
2455 * There is a new `languagevariants` siprop for action=query&meta=siteinfo,
2456 which returns a list of languages with active LanguageConverter instances.
2457 * action=query&query=allpages will no longer filter redirects using a database
2458 query in miser mode. This may result in less results being returned than were
2459 requested.
2460
2461 === Action API internal changes in 1.29 ===
2462 * New methods were added to ApiBase to handle errors and warnings using i18n
2463 keys. Methods for using hard-coded English messages were deprecated:
2464 * ApiBase::dieUsage() was deprecated
2465 * ApiBase::dieUsageMsg() was deprecated
2466 * ApiBase::dieUsageMsgOrDebug() was deprecated
2467 * ApiBase::getErrorFromStatus() was deprecated
2468 * ApiBase::parseMsg() was deprecated
2469 * ApiBase::setWarning() was deprecated
2470 * ApiBase::$messageMap is no longer public. Code attempting to access it will
2471 result in a PHP fatal error.
2472 * The $message parameter to the ApiCheckCanExecute hook should be set to an
2473 ApiMessage. This is compatible with MediaWiki 1.27 and later. Returning a
2474 code for ApiBase::parseMsg() will no longer work.
2475 * UsageException is deprecated in favor of ApiUsageException. For the time
2476 being ApiUsageException is a subclass of UsageException to allow things that
2477 catch only UsageException to still function properly.
2478 * If, for some strange reason, code was using an ApiErrorFormatter instead of
2479 ApiErrorFormatter_BackCompat, note that the result format has changed and
2480 various methods now take a module path rather than a module name.
2481 * ApiMessageTrait::getApiCode() now strips 'apierror-' and 'apiwarn-' prefixes
2482 from the message key, and maps some message keys for backwards compatibility.
2483 * API parameters may now be marked as "sensitive" to keep their values out of
2484 the logs.
2485
2486 === Languages updated in 1.29 ===
2487
2488 MediaWiki supports over 350 languages. Many localisations are updated
2489 regularly. Below only new and removed languages are listed, as well as
2490 changes to languages because of Phabricator reports.
2491
2492 * Based as always on linguistic studies on intelligibility and language
2493 knowledge by geography, language fallbacks have been expanded. When a
2494 translation is missing in the user's preferred interface language, the
2495 corresponding translation for the fallback language will be used instead.
2496 English will only be used as last resort when there are no translations.
2497 Some configurations (such as date formats and gender namespaces) have also
2498 been updated when using the fallback language's configuration was inadequate.
2499 The new or reinstated language fallbacks are (after cs ↔ sk in 1.28):
2500 ca ↔ oc; hsb ↔ dsb; io → eo; mdf → ru; pnt → el; roa-tara → it; rup → ro;
2501 sh → bs, sr-el, hr.
2502 * (T137376) New language support: Atikamekw (atj).
2503 * (T163600) New language support: Dinka (din).
2504 * (T155957) Talk Namespaces for Javanese language (jv) have been updated.
2505
2506 ==== No fallback for Ukrainian ====
2507 * (T39314) The fallback from Ukrainian to Russian was removed. The Ukrainian
2508 language will now use the default fallback language: English. When a
2509 translation to Ukrainian is not available, an English string will be shown.
2510
2511 === Other changes in 1.29 ===
2512 * Database::getSearchEngine() (deprecated in 1.28) was removed. Use
2513 SearchEngineFactory::getSearchEngineClass() instead.
2514 * $wgSessionsInMemcached (deprecated in 1.20) was removed. No replacement is
2515 required as all sessions are stored in Object Cache now.
2516 * MWHttpRequest::execute() should be considered to return a StatusValue; the
2517 Status return type is deprecated.
2518 * User::edits() (deprecated in 1.21) was removed.
2519 * Xml::escapeJsString() (deprecated in 1.21) was removed.
2520 * Article::getText() and Article::prepareTextForEdit() (deprecated in 1.21)
2521 were removed.
2522 * Article::getAutosummary() and WikiPage::getAutosummary() (deprecated in 1.21)
2523 were removed.
2524 * Hook ArticleViewCustom (deprecated in 1.21) was removed. Use
2525 ArticleContentViewCustom instead.
2526 * Hooks EditPageGetDiffText and ShowRawCssJs (deprecated in 1.21) were removed.
2527 * Class RevisiondeleteAction (deprecated in 1.25) was removed.
2528 * WikiPage::prepareTextForEdit() (deprecated in 1.21) was removed.
2529 * WikiPage::getText() (deprecated in 1.21) was removed.
2530 * Article::fetchContent() (deprecated in 1.21) was removed.
2531 * User::getPassword() (deprecated in 1.27) was removed.
2532 * User::getTemporaryPassword() (deprecated in 1.27) was removed.
2533 * User::isPasswordReminderThrottled() (deprecated in 1.27) was removed.
2534 * Class FSRepo (deprecated in 1.19) was removed.
2535 * WebRequest::checkSessionCookie() (deprecated in 1.27) was removed. Use
2536 \MediaWiki\Session\SessionManager::singleton()->getPersistedSessionId()
2537 instead.
2538 * Class ImageGallery (deprecated in 1.22) was removed.
2539 Use ImageGalleryBase::factory instead.
2540 * Title::moveNoAuth() (deprecated in 1.25) was removed. Use MovePage class
2541 instead.
2542 * Hook UnknownAction (deprecated in 1.19) was actually deprecated (it will now
2543 emit warnings). Create a subclass of Action and add it to $wgActions instead.
2544 * WikiRevision::getText() (deprecated since 1.21) is no longer marked
2545 deprecated.
2546 * Linker::getInterwikiLinkAttributes() (deprecated since 1.25) was removed.
2547 * Linker::getInternalLinkAttributes() (deprecated since 1.25) was removed.
2548 * Linker::getInternalLinkAttributesObj() (deprecated since 1.25) was removed.
2549 * Linker::getLinkAttributesInternal() (deprecated since 1.25) was removed.
2550 * RedisConnectionPool::handleException (deprecated since 1.23) was removed.
2551 * The static properties mw.Api.errors and mw.Api.warnings, containing incomplete
2552 and outdated lists of errors/warnings returned by the API, are now deprecated.
2553 * wiki.phtml entry point was removed. Refer to index.php instead. If you want
2554 "wiki.phtml" URLs to continue to work, set up redirects. In Apache, this can
2555 be done by enabling mod_rewrite and adding the following rules to your
2556 configuration:
2557
2558 RewriteEngine On
2559 RewriteBase /
2560 RewriteRule ^/w/wiki\.phtml$ /w/index.php [R=301,L]
2561 * Hook ArticleAfterFetchContent (deprecated in 1.21) was removed.
2562 Use ArticleAfterFetchContentObject instead.
2563 * Hook ArticleInsertComplete (deprecated in 1.21) was removed.
2564 Use PageContentInsertComplete instead.
2565 * Hook ArticleSave (deprecated in 1.21) was removed.
2566 Use PageContentSave instead.
2567 * Hook ArticleSaveComplete (deprecated in 1.21) was removed.
2568 Use PageContentSaveComplete instead.
2569 * Hook EditFilterMerged (deprecated in 1.21) was removed.
2570 Use EditFilterMergedContent instead.
2571 * Hook EditPageGetPreviewText (deprecated in 1.21) was removed.
2572 Use EditPageGetPreviewContent instead.
2573 * Hook TitleIsCssOrJsPage (deprecated in 1.21) was removed.
2574 Use ContentHandlerDefaultModelFor instead.
2575 * Hook TitleIsWikitextPage (deprecated in 1.21) was removed.
2576 Use ContentHandlerDefaultModelFor instead.
2577 * Article::getContent() (deprecated in 1.21) was removed.
2578 * Revision::getText() (deprecated in 1.21) was removed.
2579 * Article::doEdit() and WikiPage::doEdit() (deprecated in 1.21) were removed.
2580 * Parser::replaceUnusualEscapes() (deprecated in 1.24) was removed.
2581 * Article::doEditContent() was marked as deprecated, to be removed in 1.30
2582 or later.
2583 * ContentHandler::runLegacyHooks() was removed.
2584 * refreshLinks.php now can be limited to a particular category with
2585 --category=... or a tracking category with --tracking-category=...
2586 * User-like objects that are passed to SpecialUserRights and its subclasses are
2587 now required to have a getGroupMemberships() method. See UserRightsProxy for
2588 an example.
2589 * User::$mGroups (instance variable) was marked private. Use User::getGroups()
2590 instead.
2591 * User::getGroupName(), User::getGroupMember(), User:getGroupPage(),
2592 User::makeGroupLinkHTML(), and User::makeGroupLinkWiki() were deprecated.
2593 Use equivalent methods on the UserGroupMembership class.
2594 * Maintenance scripts and tests that call User::addGroup() must now ensure that
2595 User objects have been added to the database prior to calling addGroup().
2596 * Protected function UsersPager::getGroups() was removed, and protected function
2597 UsersPager::buildGroupLink() was changed from a static to an instance method.
2598 * The third parameter ($cache) to the UsersPagerDoBatchLookups hook was changed;
2599 see docs/hooks.txt.
2600 * User::crypt() (deprecated in 1.24) was removed.
2601 * User::comparePasswords() (deprecated in 1.24) was removed.
2602 * ArchivedFile::getUserText() (deprecated in 1.23) was removed.
2603 * HTMLFileCache::newFromTitle() (deprecated in 1.24) was removed.
2604 * BREAKING CHANGE: Internal signature changes to ChangesListSpecialPage
2605 and subclasses. It should only break if you call buildMainQueryConds
2606 (changed to buildQuery with new signature) or doMainQuery (new
2607 signature). Subclasses are likely to call at least doMainQuery
2608 (possibly both), but other classes might too, because they were
2609 public.
2610 Also, some related hooks were deprecated, but this is not yet a
2611 breaking change.
2612 * Removed 'jquery.arrowSteps' module. (deprecated since 1.28)
2613 * The 'jquery.autoEllipsis' ResourceLoader module is now deprecated.
2614 * WikiRevision::$fileIsTemp was deprecated.
2615 * WikiRevision::$importer was deprecated.
2616 * WikiRevision::$user was deprecated.
2617 * Article::getLastPurgeTimestamp(), WikiPage::getLastPurgeTimestamp(), and the
2618 WikiPage::PURGE_* constants are deprecated, and the functions will always
2619 return false. They were a hack for an issue that has since been fixed.
2620 * Hook 'EditPageBeforeEditChecks' is now deprecated. Instead use the new hook
2621 'EditPageGetCheckboxesDefinition', or 'EditPage::showStandardInputs:options'
2622 if you don't actually care about checkboxes and just want to add some HTML
2623 to the page.
2624 * Selflinks are now rendered as href-less <a> tags with the class mw-selflink
2625 rather than <strong> tags. The old class name, "selflink", was deprecated
2626 and will be removed in a future release. (T160480)
2627 * (T156184) $wgRawHtml will no longer apply to internationalization messages.
2628 * Browser support for non-ES5 JavaScript browsers, including Android 2,
2629 Opera <12.10, and Internet Explorer 9, was lowered from Grade A to Grade C.
2630 * Removed wikibits global methods deprecated since MediaWiki 1.17 (T122755):
2631 is_gecko, is_chrome_mac, is_chrome, webkit_version, is_safari_win, is_safari,
2632 webkit_match, is_ff2, ff2_bugs, is_ff2_win, is_ff2_x11, opera95_bugs,
2633 opera7_bugs, opera6_bugs, is_opera_95, is_opera_preseven, is_opera,
2634 ie6_bugs, clientPC, changeText, killEvt, addHandler, hookEvent,
2635 addClickHandler, removeHandler, getElementsByClassName, getInnerText,
2636 setupCheckboxShiftClick, addCheckboxClickHandlers, mwEditButtons,
2637 mwCustomEditButtons, injectSpinner, removeSpinner, escapeQuotes,
2638 escapeQuotesHTML, jsMsg, addPortletLink, appendCSS, tooltipAccessKeyPrefix,
2639 tooltipAccessKeyRegexp, updateTooltipAccessKeys.
2640 * The ID of the <li> element containing the login link has changed from
2641 'pt-login' to 'pt-login-private' in private wikis.
2642 * The old, neglected "bulletin board style toolbar" in the edit form is now
2643 deprecated (T30856). This old code dates from 2006, and was replaced in the
2644 MediaWiki release tarball and in Wikimedia production by the WikiEditor
2645 extension in 2010. It is only shown to users if no other editor was
2646 installed, and leads to confusion.
2647 * (T92459) Loading ResourceLoader modules containing JavaScript through
2648 addModuleStyles() is deprecated and will log a warning server-side.
2649
2650 = MediaWiki 1.28 =
2651
2652 == MediaWiki 1.28.3 ==
2653
2654 This is a security and maintenance release of the MediaWiki 1.28 branch.
2655
2656 === Changes since 1.28.2 ==
2657 * (T168856) Allow SVGs created by Dia to be uploaded.
2658 * (T157545) Add missing doUpdates() call to refreshLinks.php.
2659 * (T165714) (T100085) Better handling of jobs execution in post-connection
2660 shutdown.
2661 * (T154425) (T154438) (T157679) Use AutoCommitUpdate instead of
2662 Database->onTransactionIdle.
2663 * (T154425) Make DeferredUpdates detect LBFactory transaction rounds.
2664 * (T149454) Restore erroneously removed realTableName call from
2665 DatabasePostgres.
2666 * (T167798) Fix phrase search and highlighting for phrase queries.
2667 * (T151136) Provide credits information to callbacks in extension registration.
2668 * (T160462) Allow namespaces defined in extension.json to be overwritten
2669 locally.
2670 * (T168337) Fix ErrorPageError to work from non-UI contexts.
2671 * (T143788) Backports for PHP 7.0 and 7.1 support.
2672 * (T175439) Unbreak Postgres Updater when setting defaults for a column.
2673 * (T160298) Remove use of implicitGroupBy() in ActiveUsersPager.
2674 * (T174255) Declare uploadCount property in importDump.php.
2675 * (T180231) SECURITY: Updated dev dependancy phpunit/phpunit from v4.8.24 to
2676 v4.8.36.
2677 * (T178451) SECURITY: Potential XSS when $wgShowExceptionDetails = false and
2678 browser sends non-standard url escaping.
2679 * (T165846) SECURITY: BotPassword login attempts weren't throttled.
2680 * (T128209) SECURITY: Reflected File Download from api.php.
2681 * (T134100) SECURITY: Do not reveal if user exists during login failure.
2682 * (T176247) SECURITY: Ensure Message::rawParams can't lead to XSS.
2683 * (T125163) SECURITY: Make anchor for headlines escape > and <.
2684 * (T180237) SECURITY: Protect vendor folder with .htaccess.
2685 * (T180231) SECURITY: Remove PHPUnit file with known RCE if exists in
2686 update.php.
2687 * (T124404) SECURITY: XSS in langconverter when regex hits pcre.backtrack_limit.
2688 * (T119158) SECURITY: Handle -{}- syntax in attributes safely.
2689
2690 == MediaWiki 1.28.2 ==
2691
2692 Due to a packaging error, the wrong version of the SyntaxHighlight extension was
2693 included in the tarball version of MediaWiki 1.28.1. The version included had a
2694 serious security issue in it (T158689). There was also some minor code fixes in
2695 MediaWiki itself since 1.28.1, but none of them were security relevant.
2696
2697 == MediaWiki 1.28.1 ==
2698
2699 This is a security and maintenance release of the MediaWiki 1.28 branch.
2700
2701 === Changes since 1.28.0 ===
2702
2703 * $wgRunJobsAsync is now false by default (T142751). This change only affects
2704 wikis with $wgJobRunRate > 0.
2705 * Fix fatal from "WaitConditionLoop" not being found, experienced when a wiki
2706 has more than one database server setup.
2707 * (T152717) Better escaping for PHP mail() command,
2708 * (T154670) A missing method causing the MySQL installer to fatal in rare
2709 circumstances was restored.
2710 * (T154672) Un-deprecate ArticleAfterFetchContentObject hook.
2711 * (T158766) Avoid SQL error on MSSQL when using selectRowCount().
2712 * (T145635) Fix too long index error when installing with MSSQL.
2713 * (T156184) $wgRawHtml will no longer apply to internationalization messages.
2714 * (T160519) CACHE_ANYTHING will not be CACHE_ACCEL if no accelerator is
2715 installed.
2716 * (T154872) Fix incorrect ar_usertext_timestamp index names in new 1.28
2717 installs.
2718 * (T109140) (T122209) SECURITY: Special:UserLogin and Special:Search allow
2719 redirect to interwiki links.
2720 * (T144845) SECURITY: XSS in SearchHighlighter::highlightText() when
2721 $wgAdvancedSearchHighlighting is true.
2722 * (T125177) SECURITY: API parameters may now be marked as "sensitive" to keep
2723 their values out of the logs.
2724 * (T150044) SECURITY: "Mark all pages visited" on the watchlist now requires a
2725 CSRF token.
2726 * (T156184) SECURITY: Escape content model/format url parameter in message.
2727 * (T151735) SECURITY: SVG filter evasion using default attribute values in DTD
2728 declaration.
2729 * (T161453) SECURITY: LocalisationCache will no longer use the temporary
2730 directory in it's fallback chain when trying to work out where to write the
2731 cache.
2732 * (T48143) SECURITY: Spam blacklist ineffective on encoded URLs inside file
2733 inclusion syntax's link parameter.
2734 * (T108138) SECURITY: Sysops can undelete pages, although the page is protected
2735 against it.
2736
2737 == MediaWiki 1.28 ==
2738
2739 === Changes since 1.28.0-rc1 ===
2740 * (T148957) Replace wgShowExceptionDetails with wgShowDBErrorBacktrace on db
2741 errors.
2742 * (T148956) Only apply wgDBschema to postgres/mssql.
2743 * (T145991) Introduce separate log action for deleting pages on move.
2744 * (T141474) (T110464) Bypass login page if no user input is required.
2745
2746 === Changes since 1.28.0-rc0 ===
2747 * (T142210) The changes to move the parser "NewPP limit report" from a HTML
2748 comment to a machine-readable JavaScript config option 'wgPageParseReport'
2749 have been undone. They caused the human-readable limit report to be shown
2750 incompletely or not at all. ParserOutput::setLimitReportData() and
2751 getLimitReportData() behave as they did in MediaWiki 1.27 again.
2752 * (T149510) Value of {{DISPLAYTITLE:}} parser function will not be used for
2753 the text of subheadings on a category page when creating it. This wasn't
2754 working correctly.
2755 * (T106793) MediaWiki will no longer try to perform a HTTP redirect to the
2756 canonical pretty URL when a non-pretty URL is used. It resulted in redirect
2757 loops in some clients and in some server configurations. This undoes a change
2758 made in MediaWiki 1.26.
2759 * (T149759) manifest_version: 2 was removed.
2760
2761 === Configuration changes in 1.28 ===
2762 * $wgSend404Code now affects status code of action=history if the page is not
2763 there.
2764 * BREAKING CHANGE: $wgHTTPProxy is now *required* for all external requests
2765 made by MediaWiki via a proxy. Relying on the http_proxy environment
2766 variable is no longer supported.
2767 * The load.php entry point now enforces the existing policy of not allowing
2768 access to session data, which includes the session user and the session
2769 user's language. If such access is attempted, an exception will be thrown.
2770 * The number of internal PBKDF2 iterations used to derive the session secret
2771 is configurable via $wgSessionPbkdf2Iterations.
2772 * Upload dialog's file upload log comment can now be configured separately for
2773 local and foreign uploads.
2774 * $wgForeignUploadTargets now defaults to `[ 'local' ]`, where `'local'`
2775 signifies local uploads. A value of `[]` (empty array) now means that
2776 no upload targets are allowed, effectively disabling the upload dialog.
2777 * The deprecated $wgEditEncoding variable has been removed; it was only used
2778 for Esperanto language character conversion. You are now recommended to use
2779 input methods provided by the UniversalLanguageSelector extension.
2780 * When $wgPingback is true, MediaWiki will periodically ping
2781 https://www.mediawiki.org/beacon with basic information about the local
2782 MediaWiki installation. This data includes, for example, the type of system,
2783 PHP version, and chosen database backend. This behavior is off by default.
2784 * When $wgEditSubmitButtonLabelPublish is true, MediaWiki will label the button
2785 to store-to-database-and-show-to-others as "Publish page"/"Publish changes";
2786 if false, the default, they will be "Save page"/"Save changes".
2787 * The 'editcontentmodel' permission is now granted to all logged-in users
2788 ('user').
2789 instead of just administrators ('sysop'). Documentation for this feature is
2790 available at <https://www.mediawiki.org/wiki/Help:ChangeContentModel>.
2791 * $wgRevisionCacheExpiry is now set to one week by default instead of being
2792 disabled.
2793 * Magic links are now disabled by default, and can be re-enabled by modifying
2794 the value of $wgEnableMagicLinks. Their usage is discouraged, but if they are
2795 manually enabled, a tracking category will be added to help identify usage and
2796 make it easier to migrate away from. If you depend upon magic link
2797 functionality, it is requested that you comment on
2798 <https://www.mediawiki.org/wiki/Requests_for_comment/Future_of_magic_links>
2799 and explain your use case(s).
2800 * New config variable $wgCSPFalsePositiveUrls to control what URLs to ignore
2801 in upcoming Content-Security-Policy feature's reporting.
2802
2803 === New features in 1.28 ===
2804 * User::isBot() method for checking if an account is a bot role account.
2805 * Added a new 'slideshow' mode for galleries.
2806 * Added a new hook, 'UserIsBot', to aid in determining if a user is a bot.
2807 * Added a new hook, 'ApiMakeParserOptions', to allow extensions to better
2808 interact with API parsing.
2809 * Added a new hook, 'UploadVerifyUpload', which can be used to reject a file
2810 upload. Unlike 'UploadVerifyFile' it provides information about upload comment
2811 and the file description page, but does not run for uploads to stash.
2812 * (T141604) Extensions can now provide a better error message when their
2813 maintenance scripts are run without the extension being installed.
2814 * (T8948) Numeric sorting in categories is now supported by setting
2815 $wgCategoryCollation to 'uca-default-u-kn' or 'uca-<langcode>-u-kn'. If you
2816 can't use UCA collations, a 'numeric' collation is also available. If
2817 migrating from another collation, you will need to run the updateCollation.php
2818 maintenance script.
2819 * Two new codes have been added to #time parser function: "xit" for days in
2820 current month, and "xiz" for days passed in the year, both in Iranian
2821 calendar.
2822 * mw.Api has a new option, useUS, to use U+001F (Unit Separator) when
2823 appropriate for sending multi-valued parameters. This defaults to true when
2824 the mw.Api instance seems to be for the local wiki.
2825 * After a client performs an action which alters a database that has replica
2826 databases, MediaWiki will wait for the replica databases to synchronize with
2827 the master database while it renders the HTML output. However, if the output
2828 is a redirect to another wiki on the wiki farm with a different domain,
2829 MediaWiki will instead alter the redirect URL to include a ?cpPosTime
2830 parameter that triggers the database synchronization when the URL is followed
2831 by the client. The same-domain case uses a new cpPosTime cookie.
2832 * Added new hooks, 'ApiQueryBaseBeforeQuery', 'ApiQueryBaseAfterQuery', and
2833 'ApiQueryBaseProcessRow', to make it easier for extensions to add 'prop' and
2834 'show' parameters to existing API query modules.
2835
2836 === External library changes in 1.28 ===
2837
2838 ==== Upgraded external libraries ====
2839 * Updated es5-shim from v4.1.5 to v4.5.8
2840 * Updated composer/semver from v1.4.1 to v1.4.2
2841 * Updated wikimedia/php-session-serializer from v1.0.3 to v1.0.4
2842
2843 ==== New external libraries ====
2844 * Added wikimedia/scoped-callback v1.0.0
2845 * Added wikimedia/wait-condition-loop v1.0.1
2846
2847 === Bug fixes in 1.28 ===
2848 * (T146496) action=history pages should return 404 HTTP error code if the page
2849 does not exist
2850 * (T137264) SECURITY: XSS in unclosed internal links
2851 * (T133147) SECURITY: Escape '<' and ']]>' in inline <style> blocks
2852 * (T133147) SECURITY: Require login to preview user CSS pages
2853 * (T132926) SECURITY: Do not allow undeleting a revision deleted file if it is
2854 the top file
2855 * (T129738) SECURITY: Make $wgBlockDisablesLogin also restrict logged in
2856 permissions
2857 * (T129738) SECURITY: Make blocks log users out if $wgBlockDisablesLogin is true
2858 * (T139670) Move 'UserGetRights' call before application of
2859 Session::getAllowedUserRights()
2860
2861 === Action API changes in 1.28 ===
2862 * Added 'maxarticlesize' property to action=query&meta=siteinfo which contains
2863 the value of $wgMaxArticleSize.
2864 * Property 'modulemessages' from action=parse&prop=modules was removed
2865 (deprecated since 1.26).
2866 * The following response properties from action=login, deprecated in 1.27, are
2867 now removed: lgtoken, cookieprefix, sessionid. Clients should handle cookies
2868 to properly manage session state.
2869 * Submitting the lgtoken and lgpassword parameters in the query string to
2870 action=login is now deprecated and outputs a warning. They should be submitted
2871 in the POST body instead.
2872 * Submitting sensitive authentication request parameters to action=clientlogin,
2873 action=createaccount, action=linkaccount, and action=changeauthenticationdata
2874 in the query string is now deprecated and outputs a warning. They should be
2875 submitted in the POST body instead.
2876 * (T141960) Multi-valued parameters may now be separated using U+001F
2877 (Unit Separator) instead of the pipe character. This will be useful if some of
2878 the multiple values need to contain pipes, e.g. for action=options.
2879 * The API will now warn if input is not NFC-normalized Unicode or if it
2880 contains invalid characters.
2881 * The 'normalized' list output by action=query and other modules that use
2882 ApiPageSet may contain entries where the 'from' value is percent-encoded as
2883 the raw value cannot be represented in a valid API response. These are
2884 indicated by a 'fromencoded' boolean alongside the existing 'from' parameter.
2885 * (T28680) action=paraminfo can now return info about all submodules of a
2886 module without listing them all explicitly.
2887 * (T146770) It is now possible to assert that the current user is a specific
2888 named user, using the 'assertuser' parameter.
2889 * (T141963) Added a 'known' property when missing-but-known titles (e.g. from
2890 the 'TitleIsAlwaysKnown' hook) are output in various modules.
2891
2892 === Action API internal changes in 1.28 ===
2893 * Added a new hook, 'ApiMakeParserOptions', to allow extensions to better
2894 interact with ApiParse and ApiExpandTemplates.
2895 * (T139565) SECURITY: API: Generate head items in the context of the given title
2896 * (T115333) SECURITY: Check read permission when loading page content in
2897 ApiParse
2898 * ApiBase::getResultData() was removed (deprecated since 1.25)
2899 * ApiBase::makeHelpArrayToString() was removed (deprecated since 1.25)
2900 * ApiBase::makeHelpMsgParameters() was removed (deprecated since 1.25)
2901 * ApiBase::makeHelpMsg() was removed (deprecated since 1.25)
2902 * ApiFormatBase::formatHTML() was removed (deprecated since 1.25)
2903 * ApiFormatBase::getNeedsRawData() was removed (deprecated since 1.25)
2904 * ApiFormatBase::getWantsHelp() was removed (deprecated since 1.25)
2905 * ApiFormatBase::setBufferResult() was removed (deprecated since 1.25)
2906 * ApiFormatBase::setHelp() was removed (deprecated since 1.25)
2907 * ApiFormatBase::setUnescapeAmps() was removed (deprecated since 1.25)
2908 * ApiMain::makeHelpMsgHeader() was removed (deprecated since 1.25)
2909 * ApiMain::reallyMakeHelpMsg() was removed (deprecated since 1.25)
2910 * ApiMain::setHelp() was removed (deprecated since 1.25)
2911 * ApiResult::beginContinuation() was removed (deprecated since 1.25)
2912 * ApiResult::cleanUpUTF8() was removed (deprecated since 1.25)
2913 * ApiResult::convertStatusToArray() was removed (deprecated since 1.25)
2914 * ApiResult::disableSizeCheck() was removed (deprecated since 1.24)
2915 * ApiResult::enableSizeCheck() was removed (deprecated since 1.24)
2916 * ApiResult::endContinuation() was removed (deprecated since 1.25)
2917 * ApiResult::getData() was removed (deprecated since 1.25)
2918 * ApiResult::getIsRawMode() was removed (deprecated since 1.25)
2919 * ApiResult::setContent() was removed (deprecated since 1.25)
2920 * ApiResult::setContinueParam() was removed (deprecated since 1.25)
2921 * ApiResult::setElement() was removed (deprecated since 1.25)
2922 * ApiResult::setGeneratorContinueParam() was removed (deprecated since 1.25)
2923 * ApiResult::setIndexedTagName_internal() was removed (deprecated since 1.25)
2924 * ApiResult::setIndexedTagName_recursive() was removed (deprecated since 1.25)
2925 * ApiResult::setMainForContinuation() was removed (deprecated since 1.25)
2926 * ApiResult::setParsedLimit() was removed (deprecated since 1.25)
2927 * ApiResult::setRawMode() was removed (deprecated since 1.25)
2928 * ApiResult::size() was removed (deprecated since 1.25)
2929 * Added new hooks, 'ApiQueryBaseBeforeQuery', 'ApiQueryBaseAfterQuery', and
2930 'ApiQueryBaseProcessRow', to make it easier for extensions to add 'prop' and
2931 'show' parameters to existing API query modules. A query module can enable
2932 these hooks by passing an array for $hookData to ApiQueryBase::select() and
2933 by calling ApiQueryBase->processRow() before adding a row's data to the
2934 result.
2935
2936 === Languages updated in 1.28 ===
2937
2938 MediaWiki supports over 375 languages. Many localisations are updated
2939 regularly. Below only new and removed languages are listed, as well as
2940 changes to languages because of Phabricator reports.
2941
2942 * (T137411) ban (Balinese), thanks to translators Adi Mayndra, Andru,
2943 BASAbali, M. Adiputra, Naval Scene, Nemo bis, NoiX180, and 아라.
2944 * (T135867) shn (Shan), thanks to translators Khun Sar, Piangpha,
2945 Saiddzone Saimawnkham, Saosukham, and Sengwan.
2946 * Czech (cs) and Slovak (sk) set as reciprocal fallbacks.
2947 * (T146744) Livvi-Karelian (olo) namespace messages created thanks to translator
2948 Ilja.mos.
2949
2950 === Other changes in 1.28 ===
2951 * (T128697) Improved handling of large diffs.
2952 * [BREAKING CHANGE] $wgExtendedLoginCookies has been removed. You can
2953 use or update a custom session provider if needed.
2954 * Deprecated APIEditBeforeSave hook in favor of EditFilterMergedContent.
2955 * The 'UploadVerification' hook is deprecated. Use 'UploadVerifyFile' instead.
2956 * SiteConfiguration::isLocalVHost() was removed (deprecated since 1.25).
2957 * The 'UserLoginComplete' hook has a new parameter to differentiate between
2958 actual login and visiting the login page while already logged in.
2959 * ResourceLoader::makeLoaderURL() was removed (deprecated since 1.24).
2960 * $.fn.liveAndTestAtStart was removed (deprecated since 1.24).
2961 * mw.util.tooltipAccessKeyPrefix was removed (deprecated since 1.24).
2962 * mw.util.tooltipAccessKeyRegexp was removed (deprecated since 1.24).
2963 * Linker::link() and Linker::linkKnown() were deprecated; please instead use
2964 MediaWiki\Linker\LinkRenderer. In addition, the LinkBegin and LinkEnd hooks
2965 were replaced by HtmlPageLinkRendererBegin and HtmlPageLinkRendererEnd
2966 respectively. See docs/hooks.txt for the specific changes needed for those
2967 hooks.
2968 * Linker::formatSize() was deprecated. Use Language::formatSize() directly.
2969 * Aliases for Linker methods, deprecated since 1.21, were removed from Skin:
2970 * Skin::commentBlock() (use Linker::commentBlock() instead)
2971 * Skin::generateRollback() (use Linker::generateRollback() instead)
2972 * Skin::link() (use MediaWiki\Linker\LinkRenderer instead)
2973 * Skin::linkKnown() (use MediaWiki\Linker\LinkRenderer instead)
2974 * Skin::userLink() (use Linker::userLink() instead)
2975 * Skin::userToolLinks() (use Linker::userToolLinks() instead)
2976 * Disabled "bug 2702" HTML tidying of parsed UI messages on wikis where Tidy is
2977 disabled.
2978 * DifferenceEngine::generateDiffBody() was removed (deprecated since 1.21).
2979 * UploadBase::stashFileGetKey() and UploadBase::stashSession() were deprecated.
2980 Use ...->stashFile()->getFileKey() instead.
2981 * "Public domain" was removed as a wiki license option from the installer, in
2982 favour of CC-0.
2983 * AuthenticationRequest::$required is now changed from REQUIRED to
2984 PRIMARY_REQUIRED on requests needed by primary providers even if all primaries
2985 need them.
2986 Primary providers are discouraged from returning multiple REQUIRED requests.
2987 * OOjs UI PHP widgets constructed with the `'infusable' => true` config option
2988 will no longer be automatically infused. You should call `OO.ui.infuse()`
2989 on them yourself from your JavaScript code.
2990 * parserTests.php has moved to tests/parser/parserTests.php
2991 * The command line options specific to parser tests have been removed from
2992 phpunit.php: --regex and --keep-uploads. Instead of --regex, use --filter.
2993 Instead of --keep-uploads, use the same option to parserTests.php, but you
2994 must specify a directory with --upload-dir.
2995 * The 'jquery.arrowSteps' ResourceLoader module is now deprecated.
2996 * IP::isConfiguredProxy() and IP::isTrustedProxy() were removed. Callers should
2997 migrate to using the same functions on a ProxyLookup instance, obtainable from
2998 MediaWikiServices.
2999 * The ArticleAfterFetchContent, ArticleInsertComplete, ArticleSave,
3000 ArticleSaveComplete, ArticleViewCustom, EditFilterMerged, EditPageGetDiffText,
3001 EditPageGetPreviewText and ShowRawCssJs hooks will now emit deprecation
3002 warnings if used.
3003 * (T68404) CSS3 attr() function with url type is no longer allowed
3004 in inline styles.
3005 * Database::getSearchEngine() is deprecated, use
3006 SearchEngineFactory::getSearchEngineClass instead.
3007
3008 == Compatibility ==
3009
3010 MediaWiki 1.28 requires PHP 5.5.9 or later. There is experimental support for
3011 HHVM 3.6.5 or later.
3012
3013 MySQL is the recommended DBMS. PostgreSQL or SQLite can also be used, but
3014 support for them is somewhat less mature. There is experimental support for
3015 Oracle and Microsoft SQL Server.
3016
3017 The supported versions are:
3018
3019 * MySQL 5.0.3 or later
3020 * PostgreSQL 8.3 or later
3021 * SQLite 3.3.7 or later
3022 * Oracle 9.0.1 or later
3023 * Microsoft SQL Server 2005 (9.00.1399)
3024
3025 == Upgrading ==
3026
3027 1.28 has several database changes since 1.27, and will not work without schema
3028 updates. Note that due to changes to some very large tables like the revision
3029 table, the schema update may take quite long (minutes on a medium sized site,
3030 many hours on a large site).
3031
3032 If upgrading from before 1.11, and you are using a wiki as a commons
3033 repository, make sure that it is updated as well. Otherwise, errors may arise
3034 due to database schema changes.
3035
3036 If upgrading from before 1.7, you may want to run refreshLinks.php to ensure
3037 new database fields are filled with data.
3038
3039 If you are upgrading from MediaWiki 1.4.x or earlier, you should upgrade to
3040 1.5 first. The upgrade script maintenance/upgrade1_5.php has been removed
3041 with MediaWiki 1.21.
3042
3043 Don't forget to always back up your database before upgrading!
3044
3045 See the file UPGRADE for more detailed upgrade instructions.
3046
3047 For notes on 1.27.x and older releases, see HISTORY.
3048
3049 == Online documentation ==
3050
3051 Documentation for both end-users and site administrators is available on
3052 MediaWiki.org, and is covered under the GNU Free Documentation License (except
3053 for pages that explicitly state that their contents are in the public domain):
3054
3055 https://www.mediawiki.org/wiki/Special:MyLanguage/Documentation
3056
3057 == Mailing list ==
3058
3059 A mailing list is available for MediaWiki user support and discussion:
3060
3061 https://lists.wikimedia.org/mailman/listinfo/mediawiki-l
3062
3063 A low-traffic announcements-only list is also available:
3064
3065 https://lists.wikimedia.org/mailman/listinfo/mediawiki-announce
3066
3067 It's highly recommended that you sign up for one of these lists if you're
3068 going to run a public MediaWiki, so you can be notified of security fixes.
3069
3070 == IRC help ==
3071
3072 There's usually someone online in #mediawiki on irc.freenode.net.
3073
3074 = MediaWiki 1.27 =
3075
3076 == MediaWiki 1.27.7 ==
3077
3078 This is a maintenance release of the MediaWiki 1.27 branch.
3079
3080 === Changes since MediaWiki 1.27.6 ===
3081 * Add missing `use MediaWiki\MediaWikiServices;` to LogEventsList.php.
3082 * Remove broken tests from ApiBlockTest.php.
3083
3084 == MediaWiki 1.27.6 ==
3085
3086 This is a security and maintenance release of the MediaWiki 1.27 branch.
3087
3088 === Changes since MediaWiki 1.27.5 ===
3089 * (T204729) WatchedItemStore::countVisitingWatchersMultiple() shouldn't query
3090 all titles when asked for none.
3091 * (T109121) Remove deprecated pear/mail_mime-decode from composer suggested
3092 libraries.
3093 * (T207241) Augment precision of updatelist time.
3094 * (T207540) Include IP address in "Login for $1 succeeded" log entry.
3095 * (T205765) Don't link to the obsolete "Extension Matrix" page in installer.
3096 * (T207603) SECURITY: User JS may no longer be loaded with mime type
3097 text/javascript if there is no account associated with the username.
3098 * (T113042) SECURITY: Do not allow loading pages raw with a text/javascript MIME
3099 type if non-admins can edit the page.
3100 * (T207541) Pass email address to mail().
3101 * (T209335) Clarify the default sidebar 'Help' link is about MediaWiki itself.
3102 * (T213359) Update mediawiki/mediawiki-codesniffer to 0.8.1.
3103 * (T208871) The hard-coded Google search form on the database error page was
3104 removed.
3105 * (T216968) Return pageid as int in both list=iwbacklinks and
3106 list=langbacklinks.
3107 * (T218608) Fix an issue that prevents Extension:OAuth working when
3108 $wgBlockDisablesLogin is true.
3109 * (T219728) Added support for new Japanese era name "Reiwa".
3110 * (T25227) SECURITY: action=logout now requires to be posted and have a csrf
3111 token.
3112 * SpecialPage::checkLoginSecurityLevel() will now preserve POST data when
3113 reauthenticating.
3114 * FormSpecialPage::execute() will now call checkLoginSecurityLevel() if
3115 getLoginSecurityLevel() returns non-false.
3116 * (T197279) SECURITY: Fix reauth in Special:ChangeEmail.
3117 * (T208881) SECURITY: blacklist CSS var().
3118 * (T209794) SECURITY: rate-limit and prevent blocked users from changing email.
3119 * (T199540) SECURITY: API: Respect $wgBlockCIDRLimit in action=block.
3120 * (T212118) SECURITY: Fix cache mode for (un)patrolled recent changes query.
3121 * (T222036, T222038) SECURITY: Add permission check for user is permitted to
3122 view the log type.
3123 * (T221739) SECURITY: resources: Patch jQuery 1.11.3 for CVE-2019-11358.
3124
3125 == MediaWiki 1.27.5 ==
3126
3127 This is a security and maintenance release of the MediaWiki 1.27 branch.
3128
3129 === Changes since 1.27.4 ===
3130 * (T169545, CVE-2018-0503) SECURITY: $wgRateLimits entry for 'user' overrides
3131 'newbie'.
3132 * (T194605, CVE-2018-0505) SECURITY: BotPasswords can bypass CentralAuth's
3133 account lock.
3134 * Upgraded Moment.js from v2.8.4 to v2.19.3.
3135 * (T160298) Fixed Special:ActiveUsers due to bad backport.
3136 * (T87572) Make FormatMetadata::flattenArrayReal() work for an associative
3137 array.
3138 * Updated list of SPDX licenses for extensions.
3139 * (T189567) the CLI installer (maintenance/install.php) learned to detect and
3140 include extensions. Pass --with-extensions to enable that feature.
3141 * (T192584) Stop incorrectly passing USE INDEX to RecentChange::newFromConds().
3142 * Add default edit rate limit of 90 edits/minute for all users.
3143 * (T196125) php-memcached 3.0 (provided with PHP 7.0) is now supported.
3144 * (T196672) The mtime of extension.json files is now able to be zero.
3145 * (T118683) Fix exception from &$user deref on HHVM in the TitleMoveComplete
3146 hook.
3147 * (T180403) Validate $length in padleft/padright parser functions.
3148 * (T143790) Make $wgEmailConfirmToEdit only affect edit actions.
3149 * Special:BotPasswords now requires reauthentication.
3150 * (T191608, T187638) Add 'logid' parameter to Special:Log.
3151 * (T193829) Indicate when a Bot Password needs reset.
3152 * (T151415) Log email changes.
3153 * (T118420) Unbreak Oracle installer.
3154
3155 == MediaWiki 1.27.4 ==
3156 This is a security and maintenance release of the MediaWiki 1.27 branch.
3157
3158 === Changes since 1.27.3 ===
3159 * (T100085) Better handling of jobs execution in post-connection shutdown.
3160 * (T141604) Support conditionally registered namespaces.
3161 * (T167798) Fix highlighting for phrase queries and phrase search.
3162 * (T151136) Provide credits information to callbacks.
3163 * (T160462) Allow namespaces defined in extension.json to be overwritten
3164 locally.
3165 * (T168856) Allow SVGs created by Dia to be uploaded.
3166 * (T144705) (T148662) Password reset link is no longer shown when no reset
3167 options are available.
3168 * (T143788) (T174262) Various backports for PHP 7.0 and 7.1 support.
3169 * (T66795) $wgUserEmailUseReplyTo is now true by default to work around
3170 restrictive DMARC policies.
3171 * DB_REPLICA constant added from REL1_28+ to ease backports to extensions and
3172 core.
3173 * (T175439) Unbreak Postgres Updater when setting defaults for a column.
3174 * (T160298) Remove use of implicitGroupBy() in ActiveUsersPager.
3175 * (T142304) Allow putting the app ID in the password for bot passwords.
3176 * Updated dev dependancy phpunit/phpunit from v4.8.24 to v4.8.36.
3177 * (T178451) SECURITY: Potential XSS when $wgShowExceptionDetails = false and
3178 browser sends non-standard url escaping.
3179 * (T165846) SECURITY: BotPassword login attempts weren't throttled.
3180 * (T128209) SECURITY: Reflected File Download from api.php.
3181 * (T134100) SECURITY: Do not reveal if user exists during login failure.
3182 * (T176247) SECURITY: Ensure Message::rawParams can't lead to XSS.
3183 * (T125163) SECURITY: Make anchor for headlines escape > and <.
3184 * (T180237) SECURITY: Protect vendor folder with .htaccess.
3185 * (T180231) SECURITY: Remove PHPUnit file with known RCE if exists in
3186 update.php.
3187 * (T124404) SECURITY: XSS in langconverter when regex hits pcre.backtrack_limit.
3188 * (T119158) SECURITY: Handle -{}- syntax in attributes safely.
3189
3190 == MediaWiki 1.27.3 ==
3191 Due to a packaging error, the wrong version of the SyntaxHighlight extension was
3192 included in the tarball version of MediaWiki 1.27.2. The version included had a
3193 serious security issue in it (T158689). There was also some minor code fixes in
3194 MediaWiki itself since 1.27.2, but none of them were security relevant.
3195
3196 === Changes since 1.27.2 ===
3197 * (T145664) Fix broken wincache merge() implementation
3198 * (T163434) Add wikimedia/testing-access-wrapper for forwards compatibility
3199 * (T153505) Fix php warnings on php 7.1 due to use of &$this
3200
3201 == MediaWiki 1.27.2 ==
3202 This is a security and maintenance release of the MediaWiki 1.27 branch.
3203
3204 ApiCreateAccount was removed in 1.27.0. It was incorrectly still marked as
3205 deprecated (rather than already removed) in the RELEASE-NOTES at the point
3206 1.27.0 was released.
3207
3208 === Changes since 1.27.1 ===
3209
3210 * (T68404) CSS3 attr() function with url type argument is no longer allowed
3211 in inline styles.
3212 * $wgRunJobsAsync is now false by default (T142751). This change only affects
3213 wikis with $wgJobRunRate > 0.
3214 * (T152717) Better escaping for PHP mail() command
3215 * Submitting the lgtoken and lgpassword parameters in the query string to
3216 action=login is now deprecated and outputs a warning. They should be submitted
3217 in the POST body instead.
3218 * Submitting sensitive authentication request parameters to action=clientlogin,
3219 action=createaccount, action=linkaccount, and action=changeauthenticationdata
3220 in the query string is now deprecated and outputs a warning. They should be
3221 submitted in the POST body instead.
3222 * (T158766) Avoid SQL error on MSSQL when using selectRowCount()
3223 * (T145635) Fix too long index error when installing with MSSQL.
3224 * (T156184) $wgRawHtml will no longer apply to internationalization messages.
3225 * (T160519) CACHE_ANYTHING will not be CACHE_ACCEL if no accelerator is
3226 installed.
3227 * (T109140) (T122209) SECURITY: Special:UserLogin and Special:Search allow
3228 redirect to interwiki links.
3229 * (T144845) SECURITY: XSS in SearchHighlighter::highlightText() when
3230 $wgAdvancedSearchHighlighting is true.
3231 * (T125177) SECURITY: API parameters may now be marked as "sensitive" to keep
3232 their values out of the logs.
3233 * (T150044) SECURITY: "Mark all pages visited" on the watchlist now requires a
3234 CSRF token.
3235 * (T156184) SECURITY: Escape content model/format url parameter in message.
3236 * (T151735) SECURITY: SVG filter evasion using default attribute values in DTD
3237 declaration.
3238 * (T161453) SECURITY: LocalisationCache will no longer use the temporary
3239 directory in it's fallback chain when trying to work out where to write the
3240 cache.
3241 * (T48143) SECURITY: Spam blacklist ineffective on encoded URLs inside file
3242 inclusion syntax's link parameter.
3243 * (T108138) SECURITY: Sysops can undelete pages, although the page is protected
3244 against it.
3245
3246 == MediaWiki 1.27.1 ==
3247
3248 This is a maintenance release of the MediaWiki 1.27 branch.
3249
3250 === Changes since 1.27.0 ===
3251 * BREAKING CHANGE: $wgHTTPProxy is now *required* for all external requests
3252 made by MediaWiki via a proxy. Relying on the http_proxy environment
3253 variable is no longer supported.
3254 * (T139565) SECURITY: API: Generate head items in the context of the given title
3255 * (T137264) SECURITY: XSS in unclosed internal links
3256 * (T133147) SECURITY: Escape '<' and ']]>' in inline <style> blocks
3257 * (T133147) SECURITY: Require login to preview user CSS pages
3258 * (T132926) SECURITY: Do not allow undeleting a revision deleted file if it is
3259 the top file
3260 * (T129738) SECURITY: Make $wgBlockDisablesLogin also restrict logged in
3261 permissions
3262 * (T129738) SECURITY: Make blocks log users out if $wgBlockDisablesLogin is true
3263 * (T115333) SECURITY: Check read permission when loading page content in
3264 ApiParse
3265 * (T57548) Remove support for $wgWellFormedXml = false, all output is now well
3266 formed
3267 * (T139670) Move 'UserGetRights' call before application of
3268 Session::getAllowedUserRights()
3269
3270 == MediaWiki 1.27.0 ==
3271
3272 === PHP version requirement in 1.27 ===
3273 As of 1.27, MediaWiki now requires PHP 5.5.9 or higher (see Compatibility
3274 section). Additionally, the following PHP extensions are required:
3275 * ctype
3276 * iconv
3277 * json
3278 * mbstring (new requirement in 1.27)
3279 * xml
3280 The following PHP extensions are strongly recommended:
3281 * openssl
3282
3283 === Configuration changes in 1.27 ===
3284 * $wgAllowMicrodataAttributes and $wgAllowRdfaAttributes were removed,
3285 now always enabled. If you use RDFa on your wiki, you now have to explicitly
3286 set $wgHtml5Version to 'HTML+RDFa 1.0' or 'XHTML+RDFa 1.0'.
3287 * $wgUseLinkNamespaceDBFields was removed.
3288 * Deprecated $wgResourceLoaderMinifierStatementsOnOwnLine and
3289 $wgResourceLoaderMinifierMaxLineLength, because there was little value in
3290 making the behavior configurable. The default values (`false` for the former,
3291 1000 for the latter) are now hard-coded.
3292 * $wgDebugDumpSqlLength was removed (deprecated in 1.24).
3293 * $wgDebugDBTransactions was removed (deprecated in 1.20).
3294 * $wgUseXVO has been removed, as it provides functionality only used by
3295 custom Wikimedia patches against Squid 2.x that probably noone uses in
3296 production anymore. There is now $wgUseKeyHeader that provides similar
3297 functionality but instead of the MediaWiki-specific X-Vary-Options header,
3298 uses the draft Key header standard.
3299 * $wgScriptExtension (and support for '.php5' entry points) was removed. See the
3300 deprecation notice in the release notes for version 1.25 for advice on how to
3301 preserve support for '.php5' entry points via URL rewriting.
3302 * Password handling via the User object has been deprecated and partially
3303 removed, pending the future introduction of AuthManager. In particular:
3304 ** expirePassword(), getPasswordExpireDate(), resetPasswordExpiration(), and
3305 getPasswordExpired() have been removed. They were unused outside of core.
3306 ** The mPassword, mNewpassword, mNewpassTime, and mPasswordExpires fields are
3307 now private and will be removed in the future.
3308 ** The getPassword() and getTemporaryPassword() methods now throw
3309 BadMethodCallException and will be removed in the future.
3310 ** The ability to pass 'password' and 'newpassword' to createNew() has been
3311 removed. The only users of it seem to have been using it to set invalid
3312 passwords, and so shouldn't be greatly affected.
3313 ** setPassword(), setInternalPassword(), and setNewpassword() have been
3314 deprecated, pending the introduction of AuthManager.
3315 ** User::randomPassword() is deprecated in favor of a new method
3316 PasswordFactory::generateRandomPasswordString()
3317 ** User::getPasswordFactory() is deprecated, callers should just create a
3318 PasswordFactory themselves.
3319 ** A new constructor, User::newSystemUser(), has been added to simplify the
3320 creation of passwordless "system" users for logged actions.
3321 * $wgMaxSquidPurgeTitles was removed.
3322 * $wgAjaxWatch was removed. This is now enabled by default.
3323 * $wgUseInstantCommons now hotlinks Commons images by default instead of
3324 downloading originals and thumbnailing them locally. This allows wikis to save
3325 on CPU and bandwidth while reducing time to first byte for pages, even without
3326 a thumbnail handler. See $wgForeignFileRepos documentation for tweaks.
3327 * (T27397) WebP is enabled by default as an uploadable filetype.
3328 * (T48998) $wgArticlePath must now be either a full url, or start with a "/".
3329 * $wgRateLimitLog was removed; use $wgDebugLogGroups['ratelimit'] instead.
3330 * Deprecated API formats dbg, txt, and yaml have been removed.
3331 * CLDRPluralRule* classes have been replaced with
3332 wikimedia/cldr-plural-rule-parser.
3333 * Removed $wgProfilePerHost, $wgUDPProfilerHost, $wgUDPProfilerPort,
3334 $wgUDPProfilerFormatString, $wgStatsMethod, $wgAggregateStatsID,
3335 $wgStatsFormatString, and $wgProfileCallTree (deprecated since 1.20).
3336 * For proper operation of LocalIdLookup with shared user tables, ensure that
3337 $wgSharedDB and $wgSharedTables are properly set even on the "central" wiki
3338 that all others are sharing from and that $wgLocalDatabases is set to the
3339 full list of sharing wikis on all those wikis.
3340 * Massive overhaul to session handling:
3341 ** $wgSessionsInObjectCache is no longer supported and must be true, due to
3342 MediaWiki\Session\SessionManager. $wgSessionHandler is similarly no longer
3343 used.
3344 ** ObjectCacheSessionHandler is removed, replaced with
3345 MediaWiki\Session\PhpSessionHandler.
3346 ** PHP session handling in general ($_SESSION, session_id(), and so on) is
3347 deprecated. Use MediaWiki\Session\SessionManager instead. A new config
3348 variable, $wgPHPSessionHandling, is available to cause use of $_SESSION to
3349 issue a deprecation warning or to cause most PHP session handling to throw
3350 exceptions.
3351 ** Deprecated UserSetCookies hook. Session-handling extensions should generally
3352 be creating a custom subclass of CookieSessionProvider. Other extensions
3353 messing with cookies can no longer count on user data being saved in cookies
3354 versus other methods.
3355 ** Deprecated UserLoadFromSession hook, extensions should create a
3356 MediaWiki\Session\SessionProvider.
3357 ** The User cannot be loaded from session until after Setup.php completes.
3358 Attempts to do so will be ignored and the User will remain unloaded.
3359 ** CSRF tokens may be fetched from the MediaWiki\Session\Session, which uses
3360 the MediaWiki\Session\Token class.
3361 * MediaWiki will now auto-create users as necessary, removing the need for
3362 extensions to do so. An 'autocreateaccount' right is added to allow
3363 auto-creation when 'createaccount' is not granted to all users.
3364 * Deprecated AuthPluginAutoCreate hook in favor of LocalUserCreated.
3365 * Most cookie-handling methods in User are deprecated.
3366 * $wgAllowAsyncCopyUploads and $CopyUploadAsyncTimeout were removed. This was an
3367 experimental feature that has never worked.
3368 * Login and createaccount tokens now vary by timestamp.
3369 * LoginForm::getLoginToken() and LoginForm::getCreateaccountToken()
3370 return a MediaWiki\Session\Token, and tokens must be checked using that
3371 class's methods.
3372 * $wgEnotifUseJobQ was removed and the job queue is always used.
3373 * The functionality of the ApiSandbox extension has been merged into core. The
3374 extension should no longer be used.
3375 * $wgPreloadJavaScriptMwUtil was removed (deprecated in 1.26).
3376 Extensions, skins, gadgets and scripts that use the mediawiki.util module must
3377 express a dependency on it.
3378 * $wgIncludeLegacyJavaScript, deprecated in MediaWiki 1.26, now defaults false.
3379 Extensions, skins, gadgets and scripts that need the mediawiki.legacy.wikibits
3380 module should express a dependency on it.
3381 * Removed configuration option $wgCopyrightIcon (deprecated since 1.18). Use
3382 $wgFooterIcons['copyright']['copyright'] instead.
3383 * If the openssl and mcrypt PHP extensions are both unavailable, secure
3384 session storage (used for login) will raise an exception. This exception may
3385 be bypassed by setting $wgSessionInsecureSecrets = true.
3386 * Massive overhaul to authentication:
3387 ** AuthPlugin and AuthPluginUser are deprecated.
3388 ** LoginForm and associated templates are deprecated. Extensions which called
3389 static LoginForm methods should be converted into authentication providers.
3390 ** The following hooks are deprecated:
3391 *** AbortAutoAccount (create a MediaWiki\Auth\PreAuthenticationProvider instead)
3392 *** AbortLogin (create a MediaWiki\Auth\PreAuthenticationProvider instead)
3393 *** AbortNewAccount (create a MediaWiki\Auth\PreAuthenticationProvider instead)
3394 *** AddNewAccount (use LocalUserCreated instead)
3395 *** AuthPluginSetup (create a MediaWiki\Auth\PrimaryAuthenticationProvider
3396 instead)
3397 *** ChangePasswordForm (use AuthChangeFormFields instead, or security levels)
3398 *** LoginUserMigrated (create a MediaWiki\Auth\PreAuthenticationProvider
3399 instead)
3400 *** UserCreateForm (create a MediaWiki\Auth\AuthenticationProvider of some type
3401 instead)
3402 *** UserLoginForm (create a MediaWiki\Auth\AuthenticationProvider of some type
3403 instead)
3404 ** The following hooks are removed:
3405 *** AbortChangePassword
3406 *** LoginPasswordResetMessage
3407 *** PrefsPasswordAudit
3408 ** The UserLoginComplete hook will no longer be called for all logins, only for
3409 those via the web UI. Use UserLoggedIn if you need to do something on all
3410 logins.
3411 ** $wgRequirePasswordforEmailChange is removed.
3412
3413 === New features in 1.27 ===
3414 * $wgDataCenterUpdateStickTTL was also added. This decides how long a user
3415 sticks to the primary DC (via cookies) after they make changes to the site.
3416 * Added a new hook, 'UserMailerTransformContent', to transform the contents
3417 of an email. This is similar to the EmailUser hook but applies to all mail
3418 sent via UserMailer.
3419 * Added a new hook, 'UserMailerTransformMessage', to transform the contents
3420 of an emai after MIME encoding.
3421 * Added a new hook, 'UserMailerSplitTo', to control which users have to be
3422 emailed separately (ie. there is a single address in the To: field) so
3423 user-specific changes to the email can be applied safely.
3424 * $wgCdnMaxageLagged was added, which limits the CDN cache TTL
3425 when any load balancer uses a DB that is lagged beyond the 'max lag'
3426 setting in the relevant section of $wgLBFactoryConf.
3427 * User::newSystemUser() may be used to simplify the creation of passwordless
3428 "system" users for logged actions from scripts and extensions.
3429 * Extensions can now return detailed error information via the API when
3430 preventing user actions using 'getUserPermissionsErrors' and similar hooks
3431 by using ApiMessage instances instead of strings for the $result value.
3432 * $wgAPIMaxLagThreshold was added to limit bot changes when databases lag
3433 becomes too high.
3434 * Skins and extensions can now use FlexBox mixins (.flex-display(@display: flex)
3435 and .flex(@grow: 1, @shrink: 1, @width: auto, @order: 1)) in Less to create
3436 cross-browser-compatible FlexBox rules. Users will still need to add fallback
3437 float rules or the like for compatibility with IE9- separately.
3438 * Added MWTimestamp::getTimezoneString() which returns the localized timezone
3439 string, if available. To localize this string, see the comments of
3440 $wgLocaltimezone in includes/DefaultSettings.php.
3441 * Added CentralIdLookup, a service that allows extensions needing a concept of
3442 "central" users to get that without having to know about specific central
3443 authentication extensions.
3444 * $wgMaxUserDBWriteDuration added to limit huge user-generated transactions.
3445 Regular web request transactions that takes longer than this are aborted.
3446 * Added a new hook, 'TitleMoveCompleting', which runs before a page move is
3447 committed.
3448 * $wgCdnReboundPurgeDelay was added to provide secondary delayed purges of URLs
3449 from CDN to mitigate DB replication lag and WAN cache purge lag.
3450 * (T49162) Installer will default to setting CACHE_ACCEL as the main cache type
3451 if it is available.
3452 * It is now possible to patrol file uploads (both for new files and new versions
3453 of existing files). Special:NewFiles has gained an option to filter by patrol
3454 status. This functionality can be disabled using $wgUseFilePatrol.
3455 * MediaWiki\Session infrastructure allows for easier use of session mechanisms
3456 other than the usual cookies.
3457 ** SessionMetadata and SessionCheckInfo hooks allow for setting and checking
3458 custom session metadata.
3459 * Added MWGrants and associated configuration settings $wgGrantPermissions and
3460 $wgGrantPermissionGroups to hold configuration for authentication features
3461 such as OAuth that want to allow restricting the user rights a user may make
3462 use of.
3463 ** If you're already using the OAuth extension, these new variables are
3464 identical to (and will replace) $wgMWOAuthGrantPermissions and
3465 $wgMWOAuthGrantPermissionGroups.
3466 * Added MWRestrictions as a class to check restrictions on a WebRequest, e.g.
3467 to assert that the request comes from a particular IP range.
3468 * Added bot passwords, a rights-restricted login mechanism for API-using bots.
3469 * Whitelisted the following HTML attributes for all elements in wikitext:
3470 aria-describedby, aria-flowto, aria-label, aria-labelledby, aria-owns.
3471 * Removed "presentation" restriction on the HTML role attribute in wikitext.
3472 All values are now allowed for the role attribute.
3473 * $wgContentHandlers now also supports callbacks to create an instance of the
3474 appropriate ContentHandler subclass.
3475 * Added $wgAuthenticationTokenVersion, which if non-null prevents the
3476 user_token database field from being exposed in cookies. Setting this would
3477 be a good idea, but will log out all current sessions.
3478 * $wgEventRelayerConfig was added, for managing PubSub event relay
3479 configuration, specifically for reliable CDN url purges.
3480 * Requests have unique IDs, equal to the UNIQUE_ID environment variable (when
3481 MediaWiki is behind Apache+mod_unique_id or something similar) or a randomly-
3482 generated 24-character string. This request ID is used to annotate log records
3483 and error messages. It is available client-side via
3484 mw.config.get( 'wgRequestId' ).
3485 The request ID supplants exception IDs. Accordingly,
3486 MWExceptionHandler::getLogId() is deprecated.
3487 * (T33313) Add a preference for watching uploads by default, also applies
3488 to API-based upload tools.
3489 * $wgJpegPixelFormat was added to override chroma subsampling for JPEG image
3490 thumbnails created via ImageMagick. Defaults to 'yuv420', providing bandwidth
3491 savings versus the previous behavior on many files.
3492 * MediaWiki\Auth infrastructure (called "AuthManager") allows for more flexible
3493 configuration of multiple authentication pieces that was possible with
3494 AuthPlugin. For example, it's now easy to plug in second-factor
3495 authentication, or add additional checks to the login process, or to support
3496 multiple login methods at once, or to support non-password-based login
3497 methods.
3498 ** Providers are configured via the global setting $wgAuthManagerConfig.
3499 ** A global, $wgDisableAuthManager, is temporarily available to disable
3500 AuthManager until extensions are ready to support it.
3501 ** New hook, AuthChangeFormFields, to adjust the form fields on
3502 AuthManager-related special pages.
3503 ** New hook, AuthManagerLoginAuthenticateAudit, for additional logging of
3504 AuthManager-related authentication requests.
3505 ** New hook, ChangeAuthenticationDataAudit, for additional logging of
3506 AuthManager-related authentication data changes.
3507 ** New hook, SecuritySensitiveOperationStatus, to work with the new mechanism
3508 for requiring a recent login before taking security-sensitive operations
3509 like changing a password.
3510 ** Two new globals, $wgChangeCredentialsBlacklist and
3511 $wgRemoveCredentialsBlacklist can be used to prevent the web UI and the API
3512 changing certain authentication data.
3513 * The file upload dialog (available if you install WikiEditor or VisualEditor)
3514 can now be configured using $wgUploadDialog.
3515
3516 === External library changes in 1.27 ===
3517
3518 ==== Upgraded external libraries ====
3519 * Updated oojs/oojs-ui from v0.12.12 to v0.13.3.
3520 * Updated composer/semver from v1.0.0 to v1.2.0.
3521 * Updated liuggio/statsd-php-client to 1.0.18.
3522 * Updated QUnit from v1.18.0 to v1.22.0.
3523
3524 ==== New external libraries ====
3525 * Added wikimedia/base-convert v1.0.1.
3526 * Added wikimedia/cldr-plural-rule-parser v1.0.0.
3527 * Added wikimedia/relpath v1.0.3.
3528 * Added wikimedia/running-stat v1.1.0.
3529 * Added wikimedia/php-session-serializer v1.0.3.
3530
3531 ==== Removed and replaced external libraries ====
3532
3533 === Bug fixes in 1.27 ===
3534 * Special:Upload will now display correct maximum allowed file size when running
3535 under HHVM (T116347).
3536 * (T54077) The APIEditBeforeSave hook will once again give only the content of
3537 the section being edited, rather than the whole revision. This reverts the
3538 change made in MediaWiki 1.22.
3539
3540 === Action API changes in 1.27 ===
3541 * Added list=allrevisions.
3542 * generator=recentchanges now has the option to generate revids.
3543 * ApiPageSet::setRedirectMergePolicy() was added. This allows generator
3544 modules to define how generator data for a redirect source gets merged
3545 into the redirect destination.
3546 * prop=imageinfo&iiprop=uploadwarning will no longer include the possibility of
3547 "was-deleted" warning.
3548 * Added difftotextpst to query=revisions which preforms a pre-save transform on
3549 the text before diffing it.
3550 * Deprecated formats dbg, txt, and yaml have been removed.
3551 * (T47988) The protect log event details now use new-style formatting.
3552 * The following response properties from action=login are deprecated, and may
3553 be removed in the future: lgtoken, cookieprefix, sessionid. Clients should
3554 handle cookies to properly manage session state.
3555 * action=login transparently allows login using bot passwords. Clients should
3556 merely need to change the username and password used after setting up a bot
3557 password.
3558 * action=upload no longer understands statuskey, asyncdownload or leavemessage.
3559 * Several changes when $wgDisableAuthManager is false:
3560 ** action=login is deprecated for uses other than bot passwords.
3561 ** list=users can now indicate if a missing username is creatable.
3562 ** action=createaccount is changed in a non-backwards-compatible manner.
3563 ** Added action=query&meta=authmanagerinfo.
3564 ** Added action=clientlogin to be used to log into the main account instead of
3565 action=login.
3566 ** Added action=linkaccount.
3567 ** Added action=unlinkaccount.
3568 ** Added action=changeauthenticationdata.
3569 ** Added action=removeauthenticationdata.
3570 ** Added action=resetpassword.
3571
3572 === Action API internal changes in 1.27 ===
3573 * ApiQueryORM removed.
3574 * The following classes have been removed:
3575 ** ApiFormatDbg
3576 ** ApiFormatTxt
3577 ** ApiFormatYaml
3578 * ApiBase::addTokenProperties() was removed (deprecated since 1.24).
3579 * ApiBase::getFinalPossibleErrors() was removed (deprecated since 1.24).
3580 * ApiBase::getFinalResultProperties() was removed (deprecated since 1.24).
3581 * ApiBase::getRequireAtLeastOneParameterErrorMessages() was removed (deprecated
3582 since 1.24).
3583 * ApiBase::getPossibleErrors() was removed (deprecated since 1.24).
3584 * ApiBase::getRequireMaxOneParameterErrorMessages() was removed (deprecated
3585 since 1.24).
3586 * ApiBase::getRequireOnlyOneParameterErrorMessages() was removed (deprecated
3587 since 1.24).
3588 * ApiBase::getResultProperties() was removed (deprecated since 1.24).
3589 * ApiBase::getTitleOrPageIdErrorMessage() was removed (deprecated since 1.24).
3590 * ApiBase::parseErrors() was removed (deprecated since 1.24).
3591 * ApiQueryBase::titleToKey(), ApiQueryBase::keyToTitle() and
3592 ApiQueryBase::keyPartToTitle() all removed (deprecated since 1.24).
3593 * ApiQueryBase::checkRowCount() was removed (deprecated since 1.24).
3594 * ApiQueryBase::getDirectionDescription() was removed (deprecated since 1.25).
3595 * ApiQuery::getGenerators() was removed (deprecated since 1.21).
3596 * ApiQuery::getModules() was removed (deprecated since 1.21).
3597 * ApiQuery::getModuleType() was removed (deprecated since 1.21).
3598 * ApiQuery::setGeneratorContinue() was removed (deprecated since 1.24).
3599 * ApiMain::getModules() was removed (deprecated since 1.21).
3600 * ApiBase::getVersion() was removed (deprecated since 1.21).
3601 * ApiMain::getShowVersions() was removed (deprecated in 1.21).
3602 * ApiMain::addModule() was removed (deprecated in 1.21).
3603 * ApiMain::addFormat() was removed (deprecated in 1.21).
3604 * ApiMain::getFormats() was removed (deprecated in 1.21).
3605 * ApiPageSet::finishPageSetGeneration() was removed (deprecated in 1.21).
3606 * ApiCreateAccount was removed.
3607
3608 === Languages updated in 1.27 ===
3609
3610 MediaWiki supports over 350 languages. Many localisations are updated
3611 regularly. Below only new and removed languages are listed, as well as
3612 changes to languages because of Phabricator reports.
3613
3614 * (T113688) Change default numerals from Gurmukhi to Arabic for Punjabi locale.
3615 * (T116020) Aliases of magic words in MessagesXx.php are sorted by usage.
3616
3617 === Other changes in 1.27 ===
3618 * Added dependency injection (DI) infrastructure, see docs/injection.txt for
3619 details.
3620 It is planned to incrementally move MediaWiki code towards using DI, using the
3621 service locator (SL) pattern as a stepping stone.
3622 * ProfilerOutputUdp was removed. Note that there is a ProfilerOutputStats class.
3623 * WikiPage::doDeleteArticleReal() and WikiPage::doDeleteArticle() now
3624 ignore the 2nd and 3rd arguments (formerly $id and $commit).
3625 * Removed "loaderScripts" option from ResourceLoaderFileModule class.
3626 * Removed ORM-like wrapper added in 1.20.
3627 * LinkCache::getGoodLinks and LinkCache::getBadLinks were removed
3628 (deprecated in 1.26).
3629 * WikiPage::doQuickEdit() was removed (deprecated since 1.21).
3630 * Removed SiteObject and SiteArray classes (deprecated in 1.21).
3631 * MessageBlobStore::getInstance() was removed (deprecated since 1.25).
3632 * (T84937) Free external links ("autolinked" urls) will now be terminated
3633 by &nbsp; and HTML entity encodings of &nbsp, <, and >.
3634 * (T36948) The default file revert message's timestamp is now in
3635 $wgLocaltimezone, instead of UTC.
3636 * The default name of the 'suppress' group page has been changed from
3637 'Project:Oversight' to 'Project:Suppress'.
3638 * DatabaseBase::resultObject() is now protected (use outside Database classes
3639 not necessary since 1.11).
3640 * Calling ResourceLoaderFileModule::readStyleFiles() without a
3641 ResourceLoaderContext instance is deprecated.
3642 * ResourceLoader::getLessCompiler() now takes an optional parameter of
3643 additional LESS variables to set for the compiler.
3644 * wfBaseConvert() marked as deprecated, use Wikimedia\base_convert() directly
3645 instead.
3646 * Obsolete maintenance scripts clearCacheStats.php and showCacheStats.php
3647 were removed. The underlying data is sent to StatsD (see $wgStatsdServer).
3648 * Removed msg_resource_links database table and associated code.
3649 * Removed msg_resource database table and associated code.
3650 * Skin::getNamespaceNotice() was removed.
3651 * wfIsConfiguredProxy() was removed (deprecated since 1.24).
3652 * wfDebugTimer() was removed (deprecated since 1.25).
3653 * wfIsTrustedProxy() was removed (deprecated since 1.24).
3654 * wfGetIP() was removed (deprecated since 1.19).
3655 * MWHookException was removed.
3656 * OutputPage::appendSubtitle() was removed (deprecated since 1.19).
3657 * OutputPage::loginToUse() was removed (deprecated since 1.19).
3658 * Article::loadContent() was removed (deprecated since 1.19).
3659 * User::editToken() was removed (deprecated since 1.19).
3660 * Removed --force-normal option of dumpBackup.php, as it no longer served
3661 any useful purpose since 1.22.
3662 * The functions processOption() and processArgs() on the BackupDumper and
3663 TextPassDumper classes have been removed.
3664 * The maintenance/backupTextPass.inc file was deleted. You should include
3665 maintenance/dumpTextPass.php instead.
3666 * WikiPage::getUsedTemplates() was removed (deprecated since 1.19).
3667 * wfEmptyMsg() was removed (deprecated since 1.18).
3668 * OutputPage::permissionRequired() was removed (deprecated since 1.18).
3669 * OutputPage::blockedPage() was removed (deprecated since 1.18).
3670 * User::getSkin() was removed (deprecated since 1.18).
3671 * OutputPage::includeJQuery() was removed (deprecated since 1.17).
3672 * WikiPage::updateRestrictions() was removed (deprecated since 1.19).
3673 * WikiPage::testPreSaveTransform() was removed (deprecated since 1.19).
3674 * LogPage::logName() was removed (deprecated since 1.19).
3675 * LogPage::logHeader() was removed (deprecated since 1.19).
3676 * wfCheckLimits() was removed (deprecated since 1.24).
3677 * Linker::makeKnownLinkObj() was removed (deprecated since 1.16).
3678 * Linker::makeLinkObj() was removed (deprecated since 1.16).
3679 * wfMsgForContentNoTrans() was removed (deprecated since 1.18).
3680 * ChangesList::usePatrol was removed (deprecated since 1.22).
3681 * wfMsgNoTrans() was removed (deprecated since 1.18).
3682 * Linker::makeImageLink2 was removed (deprecated since 1.20).
3683 * Title::userIsWatching() was removed (deprecated since 1.20).
3684 * Removed WaitForSlave maintenance script; use SELECT MASTER_POS_WAIT()
3685 database function directly instead.
3686 * wfMsg() was removed (deprecated since 1.18).
3687 * wfMsgForContent() was removed (deprecated since 1.18).
3688 * wfMsgReal() was removed (deprecated since 1.18).
3689 * wfMsgGetKey() was removed (deprecated since 1.18).
3690 * wfMsgHtml() was removed (deprecated since 1.18).
3691 * wfMsgWikiHtml() was removed (deprecated since 1.18).
3692 * wfMsgExt() was removed (deprecated since 1.18).
3693 * Language::armourMath() was removed (deprecated since 1.22).
3694 * LanguageConverter::armourMath() was removed (deprecated since 1.22).
3695 * FakeConverter::armourMath() was removed (deprecated since 1.22).
3696 * The unused jquery.validate ResourceLoader module was removed.
3697 * FileRepo::getRootUrl() was removed (deprecated since 1.20).
3698 * User::generateToken() was removed (deprecated since 1.20).
3699 * WikiPage::getRawText() was removed (deprecated since 1.21).
3700 * ParserOutput::hasCustomDataUpdates() was removed (deprecated since 1.25).
3701 * ParserOutput::addSecondaryDataUpdate() was removed (deprecated since 1.25).
3702 * ParserOutput::getSecondaryDataUpdates() was removed (deprecated since 1.25).
3703 * Gallery images with multiple caption pipes no longer concatenate them all
3704 together but instead pick the final one, similar to image syntax.
3705 * XML-like parser tags (such as <gallery>), when unclosed, will be left unparsed
3706 rather than consume everything until the end of the page.
3707 * New maintenance script resetUserEmail.php allows sysadmins to reset user
3708 emails in case a user forgot password/account was stolen.
3709 * wfCheckEntropy() was removed (deprecated in 1.27).
3710 * Browser support for Internet Explorer 8 lowered from Grade A to Grade C.
3711 * ContentHandler::supportsCategories method added. Default is true.
3712 CategoryMembershipChangeJob updates are skipped for content that
3713 does not support categories.
3714 * wikidiff difference engine is no longer supported, anyone still using it are
3715 encouraged to upgrade to wikidiff2 which is actively maintained and has better
3716 package availability.
3717 * Database logic was removed from WatchedItem and a WatchedItemStore was
3718 created:
3719 ** WatchedItem::IGNORE_USER_RIGHTS and WatchedItem::CHECK_USER_RIGHTS were
3720 deprecated. User::IGNORE_USER_RIGHTS and User::CHECK_USER_RIGHTS were
3721 introduced.
3722 ** WatchedItem::fromUserTitle was deprecated in favour of the constructor.
3723 ** WatchedItem::resetNotificationTimestamp was deprecated.
3724 ** WatchedItem::batchAddWatch was deprecated.
3725 ** WatchedItem::addWatch was deprecated.
3726 ** WatchedItem::removeWatch was deprecated.
3727 ** WatchedItem::isWatched was deprecated.
3728 ** WatchedItem::duplicateEntries was deprecated.
3729 ** EmailNotification::updateWatchlistTimestamp was deprecated.
3730 ** User::getWatchedItem was removed.
3731 * Unit tests don't work with external PHPUnit anymore, Composer is now the only
3732 supported way. Run `composer install` to install it and other dev dependencies
3733 to run unit tests.
3734 * wl_id field added to the watchlist table.
3735 * Revision::getRawText() was removed (deprecated since 1.21).
3736 * WikiPage::replaceSection() was removed (deprecated since 1.21).
3737 * Article::replaceSection() was removed (deprecated since 1.21).
3738 * Language::getLangObj() was removed (deprecated since 1.24).
3739 * Language::getLanguageName() was removed (deprecated since 1.20).
3740 * Language::getLanguageNames() was removed (deprecated since 1.20).
3741 * Language::getTranslatedLanguageNames() was removed (deprecated since 1.20).
3742 * Language::specialPage() was removed (deprecated since 1.24).
3743 * MediaWikiTestCase::assertException() was removed (deprecated since 1.22).
3744 * OutputPage::getHeadItems() was removed (deprecated since 1.24).
3745 * OutputPage::getScript() was removed (deprecated since 1.24).
3746 * OutputPage::out() was removed (deprecated since 1.22).
3747 * OutputPage::setAllowedModules() was removed (deprecated since 1.24).
3748 * UserrightsPage::makeGroupNameListForLog() was removed (deprecated since 1.21).
3749 * MediaWikiSite::newFromGlobalId() was removed (deprecated since 1.21).
3750 * Title::newFromRedirect() was removed (deprecated since 1.21).
3751 * Skin::commonPrintStylesheet() was removed (deprecated since 1.22).
3752 * Skin::getCommonStylePath() was removed (deprecated since 1.24).
3753 * Skin::newFromKey() was removed (deprecated since 1.24).
3754 * Skin::getUsableSkins() was removed (deprecated since 1.23).
3755 * LoadBalancer::pickRandom() was removed (deprecated in 1.21).
3756 * Article::getUndoText() and WikiPage::getUndoText were removed (deprecated
3757 since 1.21).
3758 * DifferenceEngine::setText() was removed (deprecated in 1.21).
3759 * Title::newFromRedirectArray() was removed (deprecated in 1.21).
3760 * UserMailer::send() no longer accepts $replyto as the 5th argument and
3761 $contentType as the 6th. These must be passed in the options array now.
3762 * Title::newFromRedirectRecurse() was removed (deprecated in 1.21).
3763 * Skin::accesskey was removed (deprecated since 1.21).
3764 * Skin::blockLink was removed (deprecated since 1.21).
3765 * Skin::buildRollbackLink was removed (deprecated since 1.21).
3766 * Skin::emailLink was removed (deprecated since 1.21).
3767 * Skin::formatComment was removed (deprecated since 1.21).
3768 * Skin::formatHiddenCategories was removed (deprecated since 1.21).
3769 * Skin::formatLinksInComment was removed (deprecated since 1.21).
3770 * Skin::formatRevisionSize was removed (deprecated since 1.21).
3771 * Skin::formatSize was removed (deprecated since 1.21).
3772 * Skin::formatTemplates was removed (deprecated since 1.21).
3773 * Skin::generateTOC was removed (deprecated since 1.21).
3774 * Skin::getInternalLinkAttributes was removed (deprecated since 1.21).
3775 * Skin::getInternalLinkAttributesObj was removed (deprecated since 1.21).
3776 * Skin::getInterwikiLinkAttributes was removed (deprecated since 1.21).
3777 * Skin::getInvalidTitleDescription was removed (deprecated since 1.21).
3778 * Skin::getLinkColour was removed (deprecated since 1.21).
3779 * Skin::getRevDeleteLink was removed (deprecated since 1.21).
3780 * Skin::getRollbackEditCount was removed (deprecated since 1.21).
3781 * Skin::makeBrokenImageLinkObj was removed (deprecated since 1.21).
3782 * Skin::makeCommentLink was removed (deprecated since 1.21).
3783 * Skin::makeExternalImage was removed (deprecated since 1.21).
3784 * Skin::makeExternalLink was removed (deprecated since 1.21).
3785 * Skin::makeHeadline was removed (deprecated since 1.21).
3786 * Skin::makeImageLink was removed (deprecated since 1.21).
3787 * Skin::makeMediaLinkFile was removed (deprecated since 1.21).
3788 * Skin::makeMediaLinkObj was removed (deprecated since 1.21).
3789 * Skin::makeSelfLinkObj was removed (deprecated since 1.21).
3790 * Skin::makeThumbLink2 was removed (deprecated since 1.21).
3791 * Skin::makeThumbLinkObj was removed (deprecated since 1.21).
3792 * Skin::normaliseSpecialPage was removed (deprecated since 1.21).
3793 * Skin::normalizeSubpageLink was removed (deprecated since 1.21).
3794 * Skin::processResponsiveImages was removed (deprecated since 1.21).
3795 * Skin::revComment was removed (deprecated since 1.21).
3796 * Skin::revDeleteLink was removed (deprecated since 1.21).
3797 * Skin::revDeleteLinkDisabled was removed (deprecated since 1.21).
3798 * Skin::revUserLink was removed (deprecated since 1.21).
3799 * Skin::revUserTools was removed (deprecated since 1.21).
3800 * Skin::specialLink was removed (deprecated since 1.21).
3801 * Skin::splitTrail was removed (deprecated since 1.21).
3802 * Skin::titleAttrib was removed (deprecated since 1.21).
3803 * Skin::tocIndent was removed (deprecated since 1.21).
3804 * Skin::tocLine was removed (deprecated since 1.21).
3805 * Skin::tocLineEnd was removed (deprecated since 1.21).
3806 * Skin::tocList was removed (deprecated since 1.21).
3807 * Skin::tocUnindent was removed (deprecated since 1.21).
3808 * Skin::tooltip was removed (deprecated since 1.21).
3809 * Skin::tooltipAndAccesskeyAttribs was removed (deprecated since 1.21).
3810 * Skin::userTalkLink was removed (deprecated since 1.21).
3811 * Skin::userToolLinksRedContribs was removed (deprecated since 1.21).
3812 * wikidiff3 is now the default and only PHP diff engine. It provides improved
3813 diff performance on complex changes. $wgExternalDiffEngine = 'wikidiff3'
3814 therefore makes no difference now. Users are still recommended to use
3815 wikidiff2 if possible, though.
3816 * User::addNewUserLogEntry() was deprecated.
3817 * User::addNewUserLogEntryAutoCreate() was deprecated.
3818 * User::isPasswordReminderThrottled() was deprecated.
3819 * Bot-oriented parameters to Special:UserLogin (wpCookieCheck,
3820 wpSkipCookieCheck) were removed.
3821 * Installer can now be customized without patching MediaWiki code, see
3822 mw-config/overrides/README for details.
3823
3824 === Compatibility ===
3825
3826 MediaWiki 1.27 requires PHP 5.5.9 or later. There is experimental support for
3827 HHVM 3.6.5 or later.
3828
3829 MySQL is the recommended DBMS. PostgreSQL or SQLite can also be used, but
3830 support for them is somewhat less mature. There is experimental support for
3831 Oracle and Microsoft SQL Server.
3832
3833 The supported versions are:
3834
3835 * MySQL 5.0.3 or later
3836 * PostgreSQL 8.3 or later
3837 * SQLite 3.3.7 or later
3838 * Oracle 9.0.1 or later
3839 * Microsoft SQL Server 2005 (9.00.1399)
3840
3841 === Upgrading ===
3842
3843 1.27 has several database changes since 1.26, and will not work without schema
3844 updates. Note that due to changes to some very large tables like the revision
3845 table, the schema update may take quite long (minutes on a medium sized site,
3846 many hours on a large site).
3847
3848 If upgrading from before 1.11, and you are using a wiki as a commons
3849 repository, make sure that it is updated as well. Otherwise, errors may arise
3850 due to database schema changes.
3851
3852 If upgrading from before 1.7, you may want to run refreshLinks.php to ensure
3853 new database fields are filled with data.
3854
3855 If you are upgrading from MediaWiki 1.4.x or earlier, you should upgrade to
3856 1.5 first. The upgrade script maintenance/upgrade1_5.php has been removed
3857 with MediaWiki 1.21.
3858
3859 Don't forget to always back up your database before upgrading!
3860
3861 See the file UPGRADE for more detailed upgrade instructions.
3862
3863 For notes on 1.26.x and older releases, see HISTORY.
3864
3865
3866 = MediaWiki 1.26 =
3867
3868 == MediaWiki 1.26.4 ==
3869
3870 This is a maintenance release of the MediaWiki 1.26 branch.
3871
3872 === Changes since 1.26.3 ===
3873 * BREAKING CHANGE: $wgHTTPProxy is now *required* for all external requests
3874 made by MediaWiki via a proxy. Relying on the http_proxy environment
3875 variable is no longer supported.
3876 * (T124163) Fixed fatal error in DifferenceEngine under HHVM.
3877 * (T139565) SECURITY: API: Generate head items in the context of the given title
3878 * (T137264) SECURITY: XSS in unclosed internal links
3879 * (T133147) SECURITY: Escape '<' and ']]>' in inline <style> blocks
3880 * (T133147) SECURITY: Require login to preview user CSS pages
3881 * (T132926) SECURITY: Do not allow undeleting a revision deleted file if it is
3882 the top file
3883 * (T129738) SECURITY: Make $wgBlockDisablesLogin also restrict logged in
3884 permissions
3885 * (T129738) SECURITY: Make blocks log users out if $wgBlockDisablesLogin is true
3886 * (T115333) SECURITY: Check read permission when loading page content in
3887 ApiParse
3888 * Remove support for $wgWellFormedXml = false, all output is now well formed
3889
3890 == MediaWiki 1.26.3 ==
3891
3892 This is a maintenance release of the MediaWiki 1.26 branch.
3893
3894 === Changes since 1.26.2 ===
3895 * (T116266) Fixed undefined property notices in DairikiDiff under HHVM.
3896 * (T123166) Fix fatal error when importing pages to titles which cannot be
3897 created, such as invalid titles or titles the user is not allowed to edit.
3898 * (T122056) Old tokens are remaining valid within a new session
3899 * (T127114) Login throttle can be tricked using non-canonicalized usernames
3900 * (T123653) Cross-domain policy regexp is too narrow
3901 * (T123071) Incorrectly identifying http link in a's href attributes, due to
3902 m modifier in regex
3903 * (T129506) MediaWiki:Gadget-popups.js isn't renderable
3904 * (T125283) Users occasionally logged in as different users after
3905 SessionManager deployment
3906 * (T103239) Patrol allows click catching and patrolling of any page
3907 * (T122807) [tracking] Check php crypto primatives
3908 * (T98313) Graphs can leak tokens, leading to CSRF
3909 * (T130947) Diff generation should use PoolCounter
3910 * (T133507) Careless use of $wgExternalLinkTarget is insecure
3911 * (T132874) API action=move is not rate limited
3912 * (T110143) strip markers can be used to get around html attribute escaping in
3913 (many?) parser tags
3914 * (T116030) Increase pbkdf2 parameter strengths
3915 * (T127420) Pbkdf2Password does not check if hash_pbkdf2() succeeded
3916 * (T126685) Globally throttle password attempts
3917
3918 == MediaWiki 1.26.2 ==
3919
3920 This is a maintenance release of the MediaWiki 1.26 branch.
3921
3922 === Changes since 1.26.1 ===
3923 * (T121892) Fix fatal error on some Special pages, introduced in 1.26.1.
3924
3925 == MediaWiki 1.26.1 ==
3926
3927 This is a maintenance release of the MediaWiki 1.26 branch.
3928
3929 === Changes since 1.26.0 ===
3930 * (T117899) SECURITY: $wgArticlePath can no longer be set to relative paths
3931 that do not begin with a slash. This enabled trivial XSS attacks.
3932 Configuration values such as "http://my.wiki.com/wiki/$1" are fine, as are
3933 "/wiki/$1". A value such as "$1" or "wiki/$1" is not and will now throw an
3934 error.
3935 * (T119309) SECURITY: Use hash_compare() for edit token comparison
3936 * (T118032) SECURITY: Don't allow cURL to interpret POST parameters starting
3937 with '@' as file uploads
3938 * (T115522) SECURITY: Passwords generated by User::randomPassword() can no
3939 longer be shorter than $wgMinimalPasswordLength
3940 * (T97897) SECURITY: Improve IP parsing and trimming. Previous behavior could
3941 result in improper blocks being issued
3942 * (T109724) SECURITY: Special:MyPage, Special:MyTalk, Special:MyContributions
3943 and related pages no longer use HTTP redirects and are now redirected by
3944 MediaWiki
3945 * Fixed ConfigException in ExpandTemplates due to AlwaysUseTidy.
3946 * Fixed stray literal \n in Special:Search.
3947 * Fix issue that breaks HHVM Repo Authorative mode.
3948 * (T120267) Work around APCu memory corruption bug
3949
3950 == MediaWiki 1.26.0 ==
3951
3952 === Configuration changes in 1.26 ===
3953 * $wgPasswordResetRoutes['email'] = true by default.
3954 * $wgEnableParserCache was deprecated, set $wgParserCacheType to CACHE_NONE
3955 instead if you want to disable the parser cache.
3956 * New-style continuation is now the default for API action=continue. Clients may
3957 use the 'rawcontinue' parameter to receive raw query-continue data, but the
3958 new style is encouraged as it's harder to implement incorrectly.
3959 * Deprecated API formats dump and wddx have been completely removed.
3960 * (T7645) The "Signature" button on the edit toolbar is now hidden by default
3961 in non-talk namespaces. A new configuration variable,
3962 $wgExtraSignatureNamespaces, controls in which subject (non-talk) namespaces
3963 the "Signature" button on the edit toolbar will be displayed.
3964 * $wgResourceLoaderUseESI was deprecated and removed. This was an experimental
3965 feature that was never enabled by default.
3966 * $wgResourceLoaderExperimentalAsyncLoading was deprecated and removed.
3967 This experimental feature was never enabled by default and is obsolete as of
3968 MediaWiki 1.26, in where ResourceLoader became fully asynchronous.
3969 * $wgMasterWaitTimeout was removed (deprecated in 1.24).
3970 * Fields in ParserOptions are now private. Use the accessors instead.
3971 * Custom LESS functions (defined via $wgResourceLoaderLESSFunctions or
3972 in extension.json) have been removed, after being deprecated in 1.24.
3973 * $wgAlwaysUseTidy has been removed.
3974 * ResetSessionID hook has been removed. Nothing seems to use it.
3975 * Certain AuthPlugin methods are deprecated in favor of new hooks:
3976 ** AuthPlugin::initUser() is replaced by LocalUserCreated.
3977 ** AuthPlugin::updateUser() is replaced by UserLoggedIn.
3978 ** AuthPlugin::updateExternalDB() is replaced by the existing UserSaveSettings.
3979 ** AuthPlugin::updateExternalDBGroups() is replaced by UserGroupsChanged.
3980 ** AuthPluginUser::isHidden() is replaced by UserIsHidden.
3981 ** AuthPluginUser::isLocked() is replaced by UserIsLocked.
3982 * The UserRights hook is deprecated in favor of the new UserGroupsChanged hook.
3983 * AuthPlugin::initUser() and AuthPlugin::updateUser() should no longer replace
3984 the passed User object.
3985 * $wgBlockAllowsUTEdit is now set to true by default. This allows
3986 blocked users to edit their talk pages unless explicitly disabled
3987 when they are being blocked.
3988
3989 === New features in 1.26 ===
3990 * (T51506) Now action=info gives estimates of actual watchers for a page.
3991 See $wgRCMaxAge, $wgWatchersMaxAge and $wgUnwatchedPageSecret
3992 to learn how to configure if needed.
3993 * Change tags can now be hidden in the interface by disabling the associated
3994 "tag-<id>" interface message.
3995 * ':' (colon) is now invalid in usernames for new accounts. Existing accounts
3996 are not affected.
3997 * Added a new hook, 'LogException', to log exceptions in nonstandard ways.
3998 * Revive the 'SpecialSearchResultsAppend' hook which occurs after the list of
3999 search results are rendered. The initial use case is to append a "give us
4000 feedback" link beneath the search results.
4001 * Added a new hook, 'RejectParserCacheValue', which allows extensions to
4002 reject an otherwise-successful parser cache lookup. The intent is to allow
4003 extensions to manage the eviction of archaic HTML output from the cache.
4004 * (T68699) The expiration of the UserID and Token login cookies
4005 ($wgExtendedLoginCookieExpiration) can be configured independently of the
4006 expiration of all other cookies ($wgCookieExpiration).
4007 * (T50519) Support for generating JPEG/PNG thumbnails from WebP images added
4008 if ImageMagick is used as image scaler ($wgUseImageMagick = true). Uploading
4009 of WebP images still disabled by default. Add $wgFileExtensions[] =
4010 'webp'; to LocalSettings.php to enable uploading of WebP images.
4011 * Added new hooks 'EnhancedChangesListModifyLineData' &
4012 'EnhancedChangesListModifyBlockLineData', to modify the data used to build
4013 lines in enhanced recentchanges and watchlist.
4014 * Caches that need purging ability now use the WANObjectCache interface.
4015 This corresponds to a new $wgMainWANCache setting, which defaults to using
4016 the $wgMainCacheType settings.
4017 * Callers needing fast light-weight data stores use $wgMainStash to select
4018 the store type from $wgObjectCaches. The default is the local database.
4019 * Interface message overrides in the MediaWiki namespace will now be cached in
4020 memcached and APC (if available), rather than memcached and local files.
4021 * Added a new hook, 'RandomPageQuery', to allow modification of the query used
4022 by Special:Random to select random pages.
4023 * $wgTransactionalTimeLimit was added, which controls the request time limit
4024 for potentially slow POST requests that need to be as atomic as possible.
4025 * ResourceLoader now loads all scripts asynchronously. The top-queue and
4026 startup modules are no longer synchronously loaded.
4027 * 'mediawiki.ui.button' styles are no longer unconditionally loaded on every
4028 page. During the deprecation period, the styles will only be loaded on pages
4029 which contain 'mw-ui-button' in their HTML. Starting in 1.28, the styles will
4030 only be loaded if explicitly required.
4031 * If search returns zero results and current search engine has a "did you mean"
4032 suggestion, results for suggestion will be shown. Can be disabled by setting
4033 $wgSearchRunSuggestedQuery to false.
4034 * Added several JavaScript libraries for uploading files to MediaWiki
4035 from the client-side. See documentation for mw.Upload and its
4036 subclasses for more information.
4037 * Added OOUI dialogs and layout for file upload interfaces. See
4038 documentation for mw.Upload.Dialog, mw.Upload.BookletLayout and its
4039 subclasses for more information.
4040
4041 === extension.json changes in 1.26 ===
4042 * (T99344) The extension.json schema is now versioned. All extensions
4043 and skins should set a "manifest_version" property corresponding to
4044 the schema version they were written for. The only supported version
4045 currently is "1".
4046 * (T102523) The error message if a non-array attribute is set was improved.
4047 * (T107646) Configuration settings can now specify how they should be merged,
4048 which is necessary for arrays using integer keys.
4049 * (T110389) Adding namespaces through extension.json now actually works
4050 * $wgNamespaceProtection can now be set in extension.json.
4051 * $wgCapitalLinkOverrides can now be set in extension.json.
4052 * (T97186) Extensions using a custom prefix for their configuration settings
4053 can now set a "_prefix" key to override the default of "wg".
4054 * (T99084) Extensions can now specify what MediaWiki core versions they
4055 depend upon.
4056 * (T105236) The extension.json schema now validates custom classes in
4057 the "ResourceModules" property properly.
4058
4059 === External library changes in 1.26 ===
4060 ==== Upgraded external libraries ====
4061 * Updated es5-shim from v4.0.0 to v4.1.5.
4062 * Updated json2 from revision 2014-02-04 to 2015-05-03.
4063 * Updated Sinon.JS from 1.10.3 to 1.15.4.
4064 * Updated jQuery Client from v1.0.0 to v2.0.0.
4065 * Updated QUnit from v1.17.1 to v1.18.0.
4066 * Updated liuggio/statsd-php-client from v1.0.12 to v1.0.16.
4067 * Updated oojs/oojs-ui from v0.11.3 to v0.12.12.
4068 * Updated wikimedia/cdb from v1.0.1 to v1.3.0.
4069 * Updated wikimedia/utfnormal from v1.0.2 to v1.0.3.
4070 * Updated wikimedia/composer-merge-plugin from v1.0.0 to v1.3.0.
4071 * Updated zordius/lightncandy from v0.18 to v0.21.
4072
4073 ==== New external libraries ====
4074 * Added composer/semver v1.0.0.
4075 * Added mediawiki/at-ease v1.1.0.
4076 * Added wikimedia/assert v0.2.2.
4077 * Added wikimedia/ip-set v1.0.1.
4078 * Added wikimedia/wrappedstring v2.0.0.
4079