Merge "Check $auth parameter in Title::isValidMoveOperation()"
[lhc/web/wiklou.git] / RELEASE-NOTES-1.25
1 Security reminder: If you have PHP's register_globals option set, you must
2 turn it off. MediaWiki will not work with it enabled.
3
4 == MediaWiki 1.25 ==
5
6 THIS IS NOT A RELEASE YET
7
8 MediaWiki 1.25 is an alpha-quality branch and is not recommended for use in
9 production.
10
11 === Configuration changes in 1.25 ===
12 * $wgPageShowWatchingUsers was removed.
13 * $wgLocalVirtualHosts has been added to replace $wgConf->localVHosts.
14 * $wgAntiLockFlags was removed.
15 * $wgJavaScriptTestConfig was removed.
16 * Edit tokens returned from User::getEditToken may change on every call. Token
17 validity must be checked by passing the user-supplied token to
18 User::matchEditToken rather than by testing for equality with a
19 newly-generated token.
20 * (T74951) The UserGetLanguageObject hook may be passed any IContextSource
21 for its $context parameter. Formerly it was documented as receiving a
22 RequestContext specifically.
23 * Profiling was restructured and $wgProfiler now requires an 'output' parameter.
24 See StartProfiler.sample for details.
25 * $wgMangleFlashPolicy was added to make MediaWiki's mangling of anything that
26 might be a flash policy directive configurable.
27 * ApiOpenSearch now supports XML output. The OpenSearchXml extension should no
28 longer be used. If extracts and page images are desired, the TextExtracts and
29 PageImages extensions are required.
30 * $wgOpenSearchTemplate is deprecated in favor of $wgOpenSearchTemplates.
31 * Edits are now prepared via AJAX as users type edit summaries. This behavior
32 can be disabled via $wgAjaxEditStash.
33 * (T46740) The temporary option $wgIncludejQueryMigrate was removed, along
34 with the jQuery Migrate library, as indicated when this option was provided in
35 MediaWiki 1.24.
36 * ProfilerStandard and ProfilerSimpleTrace were removed. Make sure that any
37 StartProfiler.php config is updated to reflect this. Xhprof is available
38 for zend/hhvm. Also, for hhvm, one can consider using its xenon profiler.
39 * Default value of $wgSVGConverters['rsvg'] now uses the 'rsvg-convert' binary
40 rather than 'rsvg'.
41 * Default value of $wgSVGConverters['ImageMagick'] now uses transparent
42 background with white fallback color, rather than just white background.
43
44 === New features in 1.25 ===
45 * (T64861) Updated plural rules to CLDR 26. Includes incompatible changes
46 for plural forms in Russian, Prussian, Tagalog, Manx and several languages
47 that fall back to Russian.
48 * (T60139) ResourceLoaderFileModule now supports language fallback
49 for 'languageScripts'.
50 * Added a new hook, "ContentAlterParserOutput", to allow extensions to modify the
51 parser output for a content object before links update.
52 * (T37785) Enhanced recent changes and extended watchlist are now default.
53 Documentation: https://meta.wikimedia.org/wiki/Help:Enhanced_recent_changes
54 and https://www.mediawiki.org/wiki/Manual:$wgDefaultUserOptions.
55 * (T69341) SVG images will no longer be base64-encoded when being embedded
56 in CSS. This results in slight size increase before gzip compression (due to
57 percent-encoding), but up to 20% decrease after it.
58 * Update jStorage to v0.4.12.
59 * MediaWiki now natively supports page status indicators: icons (or short text
60 snippets) usually displayed in the top-right corner of the page. They have
61 been in use on Wikipedia for a long time, implemented using templates and CSS
62 absolute positioning.
63 - Basic wikitext syntax: <indicator name="foo">[[File:Foo.svg|20px]]</indicator>
64 - Usage instructions: https://www.mediawiki.org/wiki/Help:Page_status_indicators
65 - Adjusting custom skins to support indicators:
66 https://www.mediawiki.org/wiki/Manual:Skinning#Page_status_indicators
67 * Edit tokens may now be time-limited: passing a maximum age to
68 User::matchEditToken will reject any older tokens.
69 * The debug logging internals have been overhauled, and are now using the
70 PSR-3 interfaces.
71 * Update CSSJanus to v1.1.1.
72 * Update lessphp to v0.5.0.
73 * Added a hook, "ApiOpenSearchSuggest", to allow extensions to provide extracts
74 and images for ApiOpenSearch output. The semantics are identical to the
75 "OpenSearchXml" hook provided by the OpenSearchXml extension.
76 * PrefixSearchBackend hook now has an $offset parameter. Combined with $limit,
77 this allows for pagination of prefix results. Extensions using this hook
78 should implement supporting behavior. Not doing so can result in undefined
79 behavior from API clients trying to continue through prefix results.
80 * Update jQuery from v1.11.1 to v1.11.2.
81 * External libraries installed via composer will now be displayed
82 on Special:Version in their own section. Extensions or skins that are
83 installed via composer will not be shown in this section as it is assumed
84 they will add the proper credits to the skins or extensions section.
85 * Update QUnit from v1.14.0 to v1.16.0.
86 * Update Moment.js from v2.8.3 to v2.8.4.
87 * Special:Tags now allows for manipulating the list of user-modifiable change
88 tags. Actually modifying the tagging of a revision or log entry is not
89 implemented yet.
90 * Added 'managetags' user right and 'ChangeTagCanCreate', 'ChangeTagCanDelete',
91 and 'ChangeTagCanCreate' hooks to allow for managing user-modifiable change
92 tags.
93 * Added 'ChangeTagsListActive' hook, to separate the concepts of "defined" and
94 "active" formerly conflated by the 'ListDefinedTags' hook.
95
96 ==== External libraries ====
97 * MediaWiki now requires certain external libraries to be installed. In the past
98 these were bundled inside the Git repository of MediaWiki core, but now they
99 need to be installed separately. For users using the tarball, this will be taken
100 care of and no action will be required. Users using Git will either need to use
101 composer to fetch dependencies or use the mediawiki/vendor repository which includes
102 all dependencies for MediaWiki core and ones used in Wikimedia deployment. Detailed
103 instructions can be found at:
104 https://www.mediawiki.org/wiki/Download_from_Git#Fetch_external_libraries
105 * The following libraries are now required:
106 ** psr/log
107 This library provides the interfaces set by the PSR-3 standard (http://www.php-fig.org/psr/psr-3/)
108 which are used by MediaWiki internally via the MWLoggerFactory class.
109 See the structured logging RfC (https://www.mediawiki.org/wiki/Requests_for_comment/Structured_logging)
110 for more background information.
111 ** cssjanus/cssjanus
112 This library was formerly bundled with MediaWiki core and has been removed.
113 It automatically flips CSS for RTL support.
114 ** leafo/lessphp
115 This library was formerly bundled with MediaWiki core and has been removed.
116 It compiles LESS files into CSS.
117 ** wikimedia/cdb
118 This library was formerly a part of MediaWiki core, and has been moved into a separate library.
119 It provides CDB functions which are used in the Interwiki and Localization caches.
120 More information about the library can be found at https://www.mediawiki.org/wiki/CDB.
121
122 === Bug fixes in 1.25 ===
123 * (T73003) No additional code will be generated to try to load CSS-embedded
124 SVG images in Internet Explorer 6 and 7, as they don't support them anyway.
125 * (T69021) On Special:BookSources, corrected validation of ISBNs (both
126 10- and 13-digit forms) containing "X".
127 * Page moving was refactored into a MovePage class. As part of that:
128 ** The AbortMove hook was removed.
129 ** MovePageIsValidMove is for extensions to specify whether a page
130 cannot be moved for technical reasons, and should not be overridden.
131 ** MovePageCheckPermissions is for checking whether the given user is
132 allowed to make the move.
133 ** Title::moveNoAuth() was deprecated. Use the MovePage class instead.
134 ** Title::moveTo() was deprecated. Use the MovePage class instead.
135 ** Title::isValidMoveOperation() broken down into MovePage::isValidMove()
136 and MovePage::checkPermissions().
137 * (T18530) Multiple autocomments are now formatted in an edit summary.
138 * (T70361) Autocomments containing "/*" are parsed correctly.
139 * The Special:WhatLinksHere page linked from 'Number of redirects to this page'
140 on action=info about a file page does not list file links anymore.
141 * (T78637) Search bar is not autofocused unless it is empty so that proper scrolling using arrow keys is possible.
142 * (T50853) Database::makeList() modified to handle 'NULL' separately when building IN clause
143 * (T85192) Captcha position modified in Usercreate template. As a result:
144 ** extrafields parameter added to Usercreate.php to insert additional data
145 ** 'extend' method added to QuickTemplate to append additional values to any field of data array
146 * (T86974) Several Title methods now load from the database when necessary
147 (instead of returning incorrect results) even when the page ID is known.
148
149 === Action API changes in 1.25 ===
150 * (T67403) XML tag highlighting is now only performed for formats
151 "xmlfm" and "wddxfm".
152 * action=paraminfo supports generalized submodules (modules=query+value),
153 querymodules and formatmodules are deprecated
154 * action=paraminfo no longer outputs descriptions and other help text by
155 default. If needed, it may be requested using the new 'helpformat' parameter.
156 * action=help has been completely rewritten, and outputs help in HTML
157 rather than plain text.
158 * Hitting api.php without specifying an action now displays only the help for
159 the main module, with links to submodule help.
160 * API help is no longer displayed on errors.
161 * 'uselang' is now a recognized API parameter; "uselang=user" may be used to
162 explicitly select the language from the current user's preferences, and
163 "uselang=content" may be used to select the wiki's content language.
164 * Default output format for the API is now jsonfm.
165 * Simplified continuation will return a "batchcomplete" property in the result
166 when a batch of pages is complete.
167 * Pretty-printed HTML output now has nicer formatting and (if available)
168 better syntax highlighting.
169 * Deprecated list=deletedrevs in favor of newly-added prop=deletedrevisions and
170 list=alldeletedrevisions.
171 * prop=revisions will gracefully continue when given too many revids or titles,
172 rather than just ignoring the extras.
173 * prop=revisions will no longer die if rvcontentformat doesn't match a
174 revision's content model; it will instead warn and omit the content.
175 * If the user has the 'deletedhistory' right, action=query's revids parameter
176 will now recognize deleted revids.
177 * prop=revisions may be used as a generator, generating revids.
178 * (T68776) format=json results will no longer be corrupted when
179 $wgMangleFlashPolicy is in effect. format=php results will cleanly return an
180 error instead of returning invalid serialized data.
181 * Generators may now return data for the generated pages when used with
182 action=query.
183 * Query page data for generator=search and generator=prefixsearch will now
184 include an "index" field, which may be used by the client for sorting the
185 search results.
186 * ApiOpenSearch now supports XML output.
187 * ApiOpenSearch will now output descriptions and URLs as array indexes 2 and 3
188 in JSON format.
189 * (T76051) list=tags will now continue correctly.
190 * (T76052) list=tags can now indicate whether a tag is defined.
191 * (T75522) list=prefixsearch now supports continuation
192 * (T78737) action=expandtemplates can now return page properties.
193 * (T78690) list=allimages now accepts multiple pipe-separated values
194 for the 'aimime' parameter.
195 * prop=info with inprop=protections will now return applicable protection types
196 with the 'restrictiontypes' key.
197 * (T85417) When resolving redirects, ApiPageSet will now add the targets of
198 interwiki redirects to the list of interwiki titles.
199 * (T85417) When outputting the list of redirect titles, a 'tointerwiki'
200 property (like the existing 'tofragment' property) will be set.
201 * Added action=managetags to allow for managing the list of
202 user-modifiable change tags. Actually modifying the tagging of a revision or
203 log entry is not implemented yet.
204 * list=tags has additional properties to indicate 'active' status and tag
205 sources.
206
207 === Action API internal changes in 1.25 ===
208 * ApiHelp has been rewritten to support i18n and paginated HTML output.
209 Most existing modules should continue working without changes, but should do
210 the following:
211 * Add an i18n message "apihelp-{$moduleName}-description" to replace getDescription().
212 * Add i18n messages "apihelp-{$moduleName}-param-{$param}" for each parameter
213 to replace getParamDescription(). If necessary, the settings array returned
214 by getParams() can use the new ApiBase::PARAM_HELP_MSG key to override the
215 message.
216 * Implement getExamplesMessages() to replace getExamples().
217 * Modules with submodules (like action=query) must have their submodules
218 override ApiBase::getParent() to return the correct parent object.
219 * The 'APIGetDescription' and 'APIGetParamDescription' hooks are deprecated,
220 and will have no effect for modules using i18n messages. Use
221 'APIGetDescriptionMessages' and 'APIGetParamDescriptionMessages' instead.
222 * Api formatters will no longer be asked to display the help screen on errors.
223 * ApiMain::getCredits() was removed. The credits are available in the
224 'api-credits' i18n message.
225 * ApiFormatBase has been changed to support i18n and syntax highlighting via
226 extensions with the new 'ApiFormatHighlight' hook. Core syntax highlighting
227 has been removed.
228 * ApiFormatBase now always buffers. Output is done when
229 ApiFormatBase::closePrinter is called.
230 * Much of the logic in ApiQueryRevisions has been split into ApiQueryRevisionsBase.
231 * The 'revids' parameter supplied by ApiPageSet will now count deleted
232 revisions as "good" if the user has the 'deletedhistory' right. New methods
233 ApiPageSet::getLiveRevisionIDs() and ApiPageSet::getDeletedRevisionIDs() are
234 provided to access just the live or just the deleted revids.
235 * Added ApiPageSet::setGeneratorData() and ApiPageSet::populateGeneratorData()
236 to allow generators to include data in the action=query result.
237 * The following methods have been deprecated and may be removed in a future
238 release:
239 * ApiBase::getDescription
240 * ApiBase::getParamDescription
241 * ApiBase::getExamples
242 * ApiBase::makeHelpMsg
243 * ApiBase::makeHelpArrayToString
244 * ApiBase::makeHelpMsgParameters
245 * ApiFormatBase::setUnescapeAmps
246 * ApiFormatBase::getWantsHelp
247 * ApiFormatBase::setHelp
248 * ApiFormatBase::formatHTML
249 * ApiFormatBase::setBufferResult
250 * ApiFormatBase::getDescription
251 * ApiMain::setHelp
252 * ApiMain::reallyMakeHelpMsg
253 * ApiMain::makeHelpMsgHeader
254 * ApiQueryImageInfo::getPropertyDescriptions
255 * The following classes have been deprecated and may be removed in a future
256 release:
257 * ApiQueryDeletedrevs
258
259 === Languages updated in 1.25 ===
260
261 MediaWiki supports over 350 languages. Many localisations are updated
262 regularly. Below only new and removed languages are listed, as well as
263 changes to languages because of Bugzilla reports.
264
265 * (T66440) Kazakh (kk) wikis should no longer forcefully reset the user's
266 interface language to kk where unexpected.
267
268 === Other changes in 1.25 ===
269 * The skin autodiscovery mechanism, deprecated in MediaWiki 1.23, has been
270 removed. See https://www.mediawiki.org/wiki/Manual:Skin_autodiscovery for
271 migration guide for creators and users of custom skins that relied on it.
272 * Javascript variables 'wgFileCanRotate' and 'wgFileExtensions' now only
273 available on Special:Upload.
274 * (T58257) Set site logo from mediawiki.skinning.interface module instead of
275 inline styles in the HTML.
276 * Removed ApiQueryUsers::getAutoGroups(). (deprecated since 1.20)
277 * Removed XmlDumpWriter::schemaVersion(). (deprecated since 1.20)
278 * Removed LogEventsList::getDisplayTitle(). (deprecated since 1.20)
279 * Removed Preferences::trySetUserEmail(). (deprecated since 1.20)
280 * Removed mw.user.name() and mw.user.anonymous() methods. (deprecated since 1.20)
281 * Removed 'ok' and 'err' parameters in the mediawiki.api modules. (deprecated
282 since 1.20)
283 * Removed 'async' parameter from the mw.Api#getCategories() method. (deprecated
284 since 1.20)
285 * Removed 'jquery.json' module. (deprecated since 1.24)
286 Use the 'json' module and global JSON object instead.
287 * Deprecated OutputPage::readOnlyPage() and OutputPage::rateLimited().
288 Also, the former will now throw an MWException if called with one or more
289 arguments.
290 * Removed hitcounters and associated code.
291 * The "temp" zone of the upload respository is now considered private. If it
292 already exists (such as under the images/ directory), please make sure that
293 the directory is not web readable (e.g. via a .htaccess file).
294 * BREAKING CHANGE: In the XML dump format used by Special:Export and
295 dumpBackup.php, the <model> and <format> tags now apprear before the <text>
296 tag, instead of after the <text> and <sha1> tags.
297 The new schema version is 0.10, the new schema URI is:
298 https://www.mediawiki.org/xml/export-0.10.xsd
299 * MWFunction::call() and MWFunction::callArray() were removed, having being
300 deprecated in 1.22.
301 * Deprecated the getInternalLinkAttributes, getInternalLinkAttributesObj,
302 and getInternalLinkAttributes methods in Linker, and removed
303 getExternalLinkAttributes method, which was deprecated in MediaWiki 1.18.
304 * Removed Sites class, which was deprecated in 1.21 and replaced by SiteSQLStore.
305 * The mw.api.getToken() method now uses action=query?meta=tokens. This will now
306 fail for custom tokens registered only via the deprecated ApiTokensGetTokenTypes
307 hook. The ApiQueryTokensRegisterTypes hook should be used for this to work.
308 * Added wgRelevantArticleId to the client-side config, for use on special pages.
309 * Deprecated the TitleIsCssOrJsPage hook. Superseded by the
310 ContentHandlerDefaultModelFor hook since MediaWiki 1.21.
311 * Deprecated the TitleIsWikitextPage hook. Superseded by the
312 ContentHandlerDefaultModelFor hook since MediaWiki 1.21.
313 * Changed parsing of variables in schema (.sql) files:
314 ** The substituted values are no longer parsed. (Formerly, several passes
315 were made for each variable, so depending on the order in which variables
316 were defined, variables might have been found inside encoded values. This
317 is no longer the case.)
318 ** Variables are no longer string encoded when the /*$var*/ syntax is used.
319 If string encoding is necessary, use the '{$var}' syntax instead.
320 ** Variable names must only consist of one or more of the characters
321 "A-Za-z0-9_".
322 ** In source text of the form '{$A}'{$B}' or `{$A}`{$B}`, where variable A
323 does not exist yet variable B does, the latter may not be replaced.
324 However, this difference is unlikely to arise in practice.
325 * (T67278) RFC, PMID, and ISBN "magic links" must be surrounded by non-word
326 characters on both sides.
327 * The FormatAutocomments hook will now receive $pre and $post as booleans,
328 rather than as strings that must be prepended or appended to $comment.
329 * (T30950, T31025) RFC, PMID, and ISBN "magic links" can no longer contain
330 newlines; but they can contain &nbsp; and other non-newline whitespace.
331 * The 'mediawiki.action.edit' ResourceLoader module no longer generates the edit
332 toolbar, which has been moved to a separate 'mediawiki.toolbar' module. If you
333 relied on this behavior, update your scripts' dependencies.
334 * HTMLForm's 'vform' display style has been separated to a subclass. Therefore:
335 * HTMLForm::isVForm() is now deprecated.
336 * You can no longer do this:
337 $form = new HTMLForm( … );
338 $form->setDisplayFormat( 'vform' ); // throws exception
339 Instead, do this:
340 $form = HTMLForm::factory( 'vform', … );
341 * Deprecated Revision methods getRawUser(), getRawUserText() and getRawComment().
342
343 == Compatibility ==
344
345 MediaWiki 1.25 requires PHP 5.3.3 or later. There is experimental support for
346 HHVM 3.3.0.
347
348 MySQL is the recommended DBMS. PostgreSQL or SQLite can also be used, but
349 support for them is somewhat less mature. There is experimental support for
350 Oracle and Microsoft SQL Server.
351
352 The supported versions are:
353
354 * MySQL 5.0.2 or later
355 * PostgreSQL 8.3 or later
356 * SQLite 3.3.7 or later
357 * Oracle 9.0.1 or later
358 * Microsoft SQL Server 2005 (9.00.1399)
359
360 == Upgrading ==
361
362 1.25 has several database changes since 1.24, and will not work without schema
363 updates. Note that due to changes to some very large tables like the revision
364 table, the schema update may take quite long (minutes on a medium sized site,
365 many hours on a large site).
366
367 If upgrading from before 1.11, and you are using a wiki as a commons
368 repository, make sure that it is updated as well. Otherwise, errors may arise
369 due to database schema changes.
370
371 If upgrading from before 1.7, you may want to run refreshLinks.php to ensure
372 new database fields are filled with data.
373
374 If you are upgrading from MediaWiki 1.4.x or earlier, you should upgrade to
375 1.5 first. The upgrade script maintenance/upgrade1_5.php has been removed
376 with MediaWiki 1.21.
377
378 Don't forget to always back up your database before upgrading!
379
380 See the file UPGRADE for more detailed upgrade instructions.
381
382 For notes on 1.24.x and older releases, see HISTORY.
383
384 == Online documentation ==
385
386 Documentation for both end-users and site administrators is available on
387 MediaWiki.org, and is covered under the GNU Free Documentation License (except
388 for pages that explicitly state that their contents are in the public domain):
389
390 https://www.mediawiki.org/wiki/Documentation
391
392 == Mailing list ==
393
394 A mailing list is available for MediaWiki user support and discussion:
395
396 https://lists.wikimedia.org/mailman/listinfo/mediawiki-l
397
398 A low-traffic announcements-only list is also available:
399
400 https://lists.wikimedia.org/mailman/listinfo/mediawiki-announce
401
402 It's highly recommended that you sign up for one of these lists if you're
403 going to run a public MediaWiki, so you can be notified of security fixes.
404
405 == IRC help ==
406
407 There's usually someone online in #mediawiki on irc.freenode.net.