Remove over/underescaping detected in Special:UserRights
[lhc/web/wiklou.git] / RELEASE-NOTES-1.25
1 Security reminder: If you have PHP's register_globals option set, you must
2 turn it off. MediaWiki will not work with it enabled.
3
4 == MediaWiki 1.25 ==
5
6 THIS IS NOT A RELEASE YET
7
8 MediaWiki 1.25 is an alpha-quality branch and is not recommended for use in
9 production.
10
11 === Configuration changes in 1.25 ===
12 * $wgPageShowWatchingUsers was removed.
13 * $wgLocalVirtualHosts has been added to replace $wgConf->localVHosts.
14 * $wgAntiLockFlags was removed.
15 * $wgJavaScriptTestConfig was removed.
16 * Edit tokens returned from User::getEditToken may change on every call. Token
17 validity must be checked by passing the user-supplied token to
18 User::matchEditToken rather than by testing for equality with a
19 newly-generated token.
20 * (T74951) The UserGetLanguageObject hook may be passed any IContextSource
21 for its $context parameter. Formerly it was documented as receiving a
22 RequestContext specifically.
23 * Profiling was restructured and $wgProfiler now requires an 'output' parameter.
24 See StartProfiler.sample for details.
25 * $wgMangleFlashPolicy was added to make MediaWiki's mangling of anything that
26 might be a flash policy directive configurable.
27 * ApiOpenSearch now supports XML output. The OpenSearchXml extension should no
28 longer be used. If extracts and page images are desired, the TextExtracts and
29 PageImages extensions are required.
30 * $wgOpenSearchTemplate is deprecated in favor of $wgOpenSearchTemplates.
31 * Edits are now prepared via AJAX as users type edit summaries. This behavior
32 can be disabled via $wgAjaxEditStash.
33 * (T46740) The temporary option $wgIncludejQueryMigrate was removed, along
34 with the jQuery Migrate library, as indicated when this option was provided in
35 MediaWiki 1.24.
36
37 === New features in 1.25 ===
38 * (T64861) Updated plural rules to CLDR 26. Includes incompatible changes
39 for plural forms in Russian, Prussian, Tagalog, Manx and several languages
40 that fall back to Russian.
41 * (T60139) ResourceLoaderFileModule now supports language fallback
42 for 'languageScripts'.
43 * Added a new hook, "ContentAlterParserOutput", to allow extensions to modify the
44 parser output for a content object before links update.
45 * (T37785) Enhanced recent changes and extended watchlist are now default.
46 Documentation: https://meta.wikimedia.org/wiki/Help:Enhanced_recent_changes
47 and https://www.mediawiki.org/wiki/Manual:$wgDefaultUserOptions.
48 * (T69341) SVG images will no longer be base64-encoded when being embedded
49 in CSS. This results in slight size increase before gzip compression (due to
50 percent-encoding), but up to 20% decrease after it.
51 * Upgrade jStorage to v0.4.12.
52 * MediaWiki now natively supports page status indicators: icons (or short text
53 snippets) usually displayed in the top-right corner of the page. They have
54 been in use on Wikipedia for a long time, implemented using templates and CSS
55 absolute positioning.
56 - Basic wikitext syntax: <indicator name="foo">[[File:Foo.svg|20px]]</indicator>
57 - Usage instructions: https://www.mediawiki.org/wiki/Help:Page_status_indicators
58 - Adjusting custom skins to support indicators:
59 https://www.mediawiki.org/wiki/Manual:Skinning#Page_status_indicators
60 * Edit tokens may now be time-limited: passing a maximum age to
61 User::matchEditToken will reject any older tokens.
62 * The debug logging internals have been overhauled, and are now using the
63 PSR-3 interfaces.
64 * Update CSSJanus to v1.1.1.
65 * Update lessphp to v0.5.0.
66 * Added a hook, "ApiOpenSearchSuggest", to allow extensions to provide extracts
67 and images for ApiOpenSearch output. The semantics are identical to the
68 "OpenSearchXml" hook provided by the OpenSearchXml extension.
69 * PrefixSearchBackend hook now has an $offset parameter. Combined with $limit,
70 this allows for pagination of prefix results. Extensions using this hook
71 should implement supporting behavior. Not doing so can result in undefined
72 behavior from API clients trying to continue through prefix results.
73 * Update jQuery from v1.11.1 to v1.11.2.
74
75 ==== External libraries ====
76 * MediaWiki now requires certain external libraries to be installed. In the past
77 these were bundled inside the Git repository of MediaWiki core, but now they
78 need to be installed separately. For users using the tarball, this will be taken
79 care of and no action will be required. Users using Git will either need to use
80 composer to fetch dependencies or use the mediawiki/vendor repository which includes
81 all dependencies for MediaWiki core and ones used in Wikimedia deployment. Detailed
82 instructions can be found at:
83 https://www.mediawiki.org/wiki/Download_from_Git#Fetch_external_libraries
84 * The following libraries are now required:
85 ** psr/log
86 This library provides the interfaces set by the PSR-3 standard (http://www.php-fig.org/psr/psr-3/)
87 which are used by MediaWiki interally by the MWLogger class.
88 See the structured logging RfC (https://www.mediawiki.org/wiki/Requests_for_comment/Structured_logging)
89 for more background information.
90 ** cssjanus/cssjanus
91 This library was formerly bundled with MediaWiki core and has been removed.
92 It automatically flips CSS for RTL support.
93 ** leafo/lessphp
94 This library was formerly bundled with MediaWiki core and has been removed.
95 It compiles LESS files into CSS.
96 ** wikimedia/cdb
97 This library was formerly a part of MediaWiki core, and has been moved into a separate library.
98 It provides CDB functions which are used in the Interwiki and Localization caches.
99 More information about the library can be found at https://www.mediawiki.org/wiki/CDB.
100
101 === Bug fixes in 1.25 ===
102 * (T73003) No additional code will be generated to try to load CSS-embedded
103 SVG images in Internet Explorer 6 and 7, as they don't support them anyway.
104 * (T69021) On Special:BookSources, corrected validation of ISBNs (both
105 10- and 13-digit forms) containing "X".
106 * Page moving was refactored into a MovePage class. As part of that:
107 ** The AbortMove hook was removed.
108 ** MovePageIsValidMove is for extensions to specify whether a page
109 cannot be moved for technical reasons, and should not be overridden.
110 ** MovePageCheckPermissions is for checking whether the given user is
111 allowed to make the move.
112 ** Title::moveNoAuth() was deprecated. Use the MovePage class instead.
113 ** Title::moveTo() was deprecated. Use the MovePage class instead.
114 ** Title::isValidMoveOperation() broken down into MovePage::isValidMove()
115 and MovePage::checkPermissions().
116 * The Special:WhatLinksHere page linked from 'Number of redirects to this page'
117 on action=info about a file page does not list file links anymore.
118 * (T78637) Search bar is not autofocused unless it is empty so that proper scrolling using arrow keys is possible.
119
120 === Action API changes in 1.25 ===
121 * (T67403) XML tag highlighting is now only performed for formats
122 "xmlfm" and "wddxfm".
123 * action=paraminfo supports generalized submodules (modules=query+value),
124 querymodules and formatmodules are deprecated
125 * action=paraminfo no longer outputs descriptions and other help text by
126 default. If needed, it may be requested using the new 'helpformat' parameter.
127 * action=help has been completely rewritten, and outputs help in HTML
128 rather than plain text.
129 * Hitting api.php without specifying an action now displays only the help for
130 the main module, with links to submodule help.
131 * API help is no longer displayed on errors.
132 * 'uselang' is now a recognized API parameter; "uselang=user" may be used to
133 explicitly select the language from the current user's preferences, and
134 "uselang=content" may be used to select the wiki's content language.
135 * Default output format for the API is now jsonfm.
136 * Simplified continuation will return a "batchcomplete" property in the result
137 when a batch of pages is complete.
138 * Pretty-printed HTML output now has nicer formatting and (if available)
139 better syntax highlighting.
140 * Deprecated list=deletedrevs in favor of newly-added prop=deletedrevisions and
141 list=alldeletedrevisions.
142 * prop=revisions will gracefully continue when given too many revids or titles,
143 rather than just ignoring the extras.
144 * prop=revisions will no longer die if rvcontentformat doesn't match a
145 revision's content model; it will instead warn and omit the content.
146 * If the user has the 'deletedhistory' right, action=query's revids parameter
147 will now recognize deleted revids.
148 * prop=revisions may be used as a generator, generating revids.
149 * (T68776) format=json results will no longer be corrupted when
150 $wgMangleFlashPolicy is in effect. format=php results will cleanly return an
151 error instead of returning invalid serialized data.
152 * Generators may now return data for the generated pages when used with
153 action=query.
154 * Query page data for generator=search and generator=prefixsearch will now
155 include an "index" field, which may be used by the client for sorting the
156 search results.
157 * ApiOpenSearch now supports XML output.
158 * ApiOpenSearch will now output descriptions and URLs as array indexes 2 and 3
159 in JSON format.
160 * (T76051) list=tags will now continue correctly.
161 * (T76052) list=tags can now indicate whether a tag is defined.
162 * (T75522) list=prefixsearch now supports continuation
163 * (T78737) action=expandtemplates can now return page properties.
164
165 === Action API internal changes in 1.25 ===
166 * ApiHelp has been rewritten to support i18n and paginated HTML output.
167 Most existing modules should continue working without changes, but should do
168 the following:
169 * Add an i18n message "apihelp-{$moduleName}-description" to replace getDescription().
170 * Add i18n messages "apihelp-{$moduleName}-param-{$param}" for each parameter
171 to replace getParamDescription(). If necessary, the settings array returned
172 by getParams() can use the new ApiBase::PARAM_HELP_MSG key to override the
173 message.
174 * Implement getExamplesMessages() to replace getExamples().
175 * Modules with submodules (like action=query) must have their submodules
176 override ApiBase::getParent() to return the correct parent object.
177 * The 'APIGetDescription' and 'APIGetParamDescription' hooks are deprecated,
178 and will have no effect for modules using i18n messages. Use
179 'APIGetDescriptionMessages' and 'APIGetParamDescriptionMessages' instead.
180 * Api formatters will no longer be asked to display the help screen on errors.
181 * ApiMain::getCredits() was removed. The credits are available in the
182 'api-credits' i18n message.
183 * ApiFormatBase has been changed to support i18n and syntax highlighting via
184 extensions with the new 'ApiFormatHighlight' hook. Core syntax highlighting
185 has been removed.
186 * ApiFormatBase now always buffers. Output is done when
187 ApiFormatBase::closePrinter is called.
188 * Much of the logic in ApiQueryRevisions has been split into ApiQueryRevisionsBase.
189 * The 'revids' parameter supplied by ApiPageSet will now count deleted
190 revisions as "good" if the user has the 'deletedhistory' right. New methods
191 ApiPageSet::getLiveRevisionIDs() and ApiPageSet::getDeletedRevisionIDs() are
192 provided to access just the live or just the deleted revids.
193 * Added ApiPageSet::setGeneratorData() and ApiPageSet::populateGeneratorData()
194 to allow generators to include data in the action=query result.
195 * The following methods have been deprecated and may be removed in a future
196 release:
197 * ApiBase::getDescription
198 * ApiBase::getParamDescription
199 * ApiBase::getExamples
200 * ApiBase::makeHelpMsg
201 * ApiBase::makeHelpArrayToString
202 * ApiBase::makeHelpMsgParameters
203 * ApiFormatBase::setUnescapeAmps
204 * ApiFormatBase::getWantsHelp
205 * ApiFormatBase::setHelp
206 * ApiFormatBase::formatHTML
207 * ApiFormatBase::setBufferResult
208 * ApiFormatBase::getDescription
209 * ApiMain::setHelp
210 * ApiMain::reallyMakeHelpMsg
211 * ApiMain::makeHelpMsgHeader
212 * ApiQueryImageInfo::getPropertyDescriptions
213 * The following classes have been deprecated and may be removed in a future
214 release:
215 * ApiQueryDeletedrevs
216
217 === Languages updated in 1.25 ===
218
219 MediaWiki supports over 350 languages. Many localisations are updated
220 regularly. Below only new and removed languages are listed, as well as
221 changes to languages because of Bugzilla reports.
222
223 * (T66440) Kazakh (kk) wikis should no longer forcefully reset the user's
224 interface language to kk where unexpected.
225
226 === Other changes in 1.25 ===
227 * The skin autodiscovery mechanism, deprecated in MediaWiki 1.23, has been
228 removed. See https://www.mediawiki.org/wiki/Manual:Skin_autodiscovery for
229 migration guide for creators and users of custom skins that relied on it.
230 * Javascript variable 'wgFileCanRotate' now only available on Special:Upload.
231 * (T58257) Set site logo from mediawiki.skinning.interface module instead of
232 inline styles in the HTML.
233 * Removed ApiQueryUsers::getAutoGroups(). (deprecated since 1.20)
234 * Removed XmlDumpWriter::schemaVersion(). (deprecated since 1.20)
235 * Removed LogEventsList::getDisplayTitle(). (deprecated since 1.20)
236 * Removed Preferences::trySetUserEmail(). (deprecated since 1.20)
237 * Removed mw.user.name() and mw.user.anonymous() methods. (deprecated since 1.20)
238 * Removed 'ok' and 'err' parameters in the mediawiki.api modules. (deprecated
239 since 1.20)
240 * Removed 'async' parameter from the mw.Api#getCategories() method. (deprecated
241 since 1.20)
242 * Removed 'jquery.json' module. (deprecated since 1.24)
243 Use the 'json' module and global JSON object instead.
244 * Deprecated OutputPage::readOnlyPage() and OutputPage::rateLimited().
245 Also, the former will now throw an MWException if called with one or more
246 arguments.
247 * Removed hitcounters and associated code.
248 * The "temp" zone of the upload respository is now considered private. If it
249 already exists (such as under the images/ directory), please make sure that
250 the directory is not web readable (e.g. via a .htaccess file).
251 * BREAKING CHANGE: In the XML dump format used by Special:Export and
252 dumpBackup.php, the <model> and <format> tags now apprear before the <text>
253 tag, instead of after the <text> and <sha1> tags.
254 The new schema version is 0.10, the new schema URI is:
255 https://www.mediawiki.org/xml/export-0.10.xsd
256 * MWFunction::call() and MWFunction::callArray() were removed, having being
257 deprecated in 1.22.
258 * Deprecated the getInternalLinkAttributes, getInternalLinkAttributesObj,
259 and getInternalLinkAttributes methods in Linker, and removed
260 getExternalLinkAttributes method, which was deprecated in MediaWiki 1.18.
261 * Removed Sites class, which was deprecated in 1.21 and replaced by SiteSQLStore.
262 * The mw.api.getToken() method now uses action=query?meta=tokens. This will now
263 fail for custom tokens registered only via the deprecated ApiTokensGetTokenTypes
264 hook. The ApiQueryTokensRegisterTypes hook should be used for this to work.
265 * Added wgRelevantArticleId to the client-side config, for use on special pages.
266 * Deprecated the TitleIsCssOrJsPage hook. Superseded by the
267 ContentHandlerDefaultModelFor hook since MediaWiki 1.21.
268 * Deprecated the TitleIsWikitextPage hook. Superseded by the
269 ContentHandlerDefaultModelFor hook since MediaWiki 1.21.
270 * Changed parsing of variables in schema (.sql) files:
271 ** The substituted values are no longer parsed. (Formerly, several passes
272 were made for each variable, so depending on the order in which variables
273 were defined, variables might have been found inside encoded values. This
274 is no longer the case.)
275 ** Variables are no longer string encoded when the /*$var*/ syntax is used.
276 If string encoding is necessary, use the '{$var}' syntax instead.
277 ** Variable names must only consist of one or more of the characters
278 "A-Za-z0-9_".
279 ** In source text of the form '{$A}'{$B}' or `{$A}`{$B}`, where variable A
280 does not exist yet variable B does, the latter may not be replaced.
281 However, this difference is unlikely to arise in practice.
282 * (T67278) RFC, PMID, and ISBN "magic links" must be surrounded by non-word
283 characters on both sides.
284 * (T30950, T31025) RFC, PMID, and ISBN "magic links" can no longer contain
285 newlines; but they can contain &nbsp; and other non-newline whitespace.
286
287 == Compatibility ==
288
289 MediaWiki 1.25 requires PHP 5.3.3 or later. There is experimental support for
290 HHVM 3.3.0.
291
292 MySQL is the recommended DBMS. PostgreSQL or SQLite can also be used, but
293 support for them is somewhat less mature. There is experimental support for
294 Oracle and Microsoft SQL Server.
295
296 The supported versions are:
297
298 * MySQL 5.0.2 or later
299 * PostgreSQL 8.3 or later
300 * SQLite 3.3.7 or later
301 * Oracle 9.0.1 or later
302 * Microsoft SQL Server 2005 (9.00.1399)
303
304 == Upgrading ==
305
306 1.25 has several database changes since 1.24, and will not work without schema
307 updates. Note that due to changes to some very large tables like the revision
308 table, the schema update may take quite long (minutes on a medium sized site,
309 many hours on a large site).
310
311 If upgrading from before 1.11, and you are using a wiki as a commons
312 repository, make sure that it is updated as well. Otherwise, errors may arise
313 due to database schema changes.
314
315 If upgrading from before 1.7, you may want to run refreshLinks.php to ensure
316 new database fields are filled with data.
317
318 If you are upgrading from MediaWiki 1.4.x or earlier, you should upgrade to
319 1.5 first. The upgrade script maintenance/upgrade1_5.php has been removed
320 with MediaWiki 1.21.
321
322 Don't forget to always back up your database before upgrading!
323
324 See the file UPGRADE for more detailed upgrade instructions.
325
326 For notes on 1.24.x and older releases, see HISTORY.
327
328 == Online documentation ==
329
330 Documentation for both end-users and site administrators is available on
331 MediaWiki.org, and is covered under the GNU Free Documentation License (except
332 for pages that explicitly state that their contents are in the public domain):
333
334 https://www.mediawiki.org/wiki/Documentation
335
336 == Mailing list ==
337
338 A mailing list is available for MediaWiki user support and discussion:
339
340 https://lists.wikimedia.org/mailman/listinfo/mediawiki-l
341
342 A low-traffic announcements-only list is also available:
343
344 https://lists.wikimedia.org/mailman/listinfo/mediawiki-announce
345
346 It's highly recommended that you sign up for one of these lists if you're
347 going to run a public MediaWiki, so you can be notified of security fixes.
348
349 == IRC help ==
350
351 There's usually someone online in #mediawiki on irc.freenode.net.