Merge "Support multiple extension-dir paths to be passed to mergeMessageFileList"
[lhc/web/wiklou.git] / RELEASE-NOTES-1.27
1 == MediaWiki 1.27 ==
2
3 THIS IS NOT A RELEASE YET
4
5 MediaWiki 1.27 is an alpha-quality branch and is not recommended for use in
6 production.
7
8 === PHP version requirement ===
9 As of 1.27, MediaWiki now requires PHP 5.5.9 or higher. This corresponds with
10 HHVM 3.1.
11
12 === Configuration changes in 1.27 ===
13 * $wgUseLinkNamespaceDBFields was removed.
14 * Deprecated $wgResourceLoaderMinifierStatementsOnOwnLine and
15 $wgResourceLoaderMinifierMaxLineLength, because there was little value in
16 making the behavior configurable. The default values (`false` for the former,
17 1000 for the latter) are now hard-coded.
18 * $wgDebugDumpSqlLength was removed (deprecated in 1.24).
19 * $wgDebugDBTransactions was removed (deprecated in 1.20).
20 * $wgUseXVO has been removed, as it provides functionality only used by
21 custom Wikimedia patches against Squid 2.x that probably noone uses in
22 production anymore. There is now $wgUseKeyHeader that provides similar
23 functionality but instead of the MediaWiki-specific X-Vary-Options header,
24 uses the draft Key header standard.
25 * $wgScriptExtension (and support for '.php5' entry points) was removed. See the
26 deprecation notice in the release notes for version 1.25 for advice on how to
27 preserve support for '.php5' entry points via URL rewriting.
28 * Password handling via the User object has been deprecated and partially
29 removed, pending the future introduction of AuthManager. In particular:
30 ** expirePassword(), getPasswordExpireDate(), resetPasswordExpiration(), and
31 getPasswordExpired() have been removed. They were unused outside of core.
32 ** The mPassword, mNewpassword, mNewpassTime, and mPasswordExpires fields are
33 now private and will be removed in the future.
34 ** The getPassword() and getTemporaryPassword() methods now throw
35 BadMethodCallException and will be removed in the future.
36 ** The ability to pass 'password' and 'newpassword' to createNew() has been
37 removed. The only users of it seem to have been using it to set invalid
38 passwords, and so shouldn't be greatly affected.
39 ** setPassword(), setInternalPassword(), and setNewpassword() have been
40 deprecated, pending the introduction of AuthManager.
41 ** User::randomPassword() is deprecated in favor of a new method
42 PasswordFactory::generateRandomPasswordString()
43 ** User::getPasswordFactory() is deprecated, callers should just create a
44 PasswordFactory themselves.
45 ** A new constructor, User::newSystemUser(), has been added to simplify the
46 creation of passwordless "system" users for logged actions.
47 * $wgMaxSquidPurgeTitles was removed.
48 * $wgAjaxWatch was removed. This is now enabled by default.
49 * $wgUseInstantCommons now hotlinks Commons images by default instead of
50 downloading originals and thumbnailing them locally. This allows wikis to save
51 on CPU and bandwidth while reducing time to first byte for pages, even without
52 a thumbnail handler. See $wgForeignFileRepos documentation for tweaks.
53 * (T27397) WebP is enabled by default as an uploadable filetype.
54 * (T48998) $wgArticlePath must now be either a full url, or start with a "/".
55 * $wgRateLimitLog was removed; use $wgDebugLogGroups['ratelimit'] instead.
56 * Deprecated API formats dbg, txt, and yaml have been removed.
57 * CLDRPluralRule* classes have been replaced with
58 wikimedia/cldr-plural-rule-parser.
59 * Removed $wgProfilePerHost, $wgUDPProfilerHost, $wgUDPProfilerPort,
60 $wgUDPProfilerFormatString, $wgStatsMethod, $wgAggregateStatsID,
61 $wgStatsFormatString, and $wgProfileCallTree (deprecated since 1.20).
62 * For proper operation of LocalIdLookup with shared user tables, ensure that
63 $wgSharedDB and $wgSharedTables are properly set even on the "central" wiki
64 that all others are sharing from and that $wgLocalDatabases is set to the
65 full list of sharing wikis on all those wikis.
66 * Massive overhaul to session handling:
67 ** $wgSessionsInObjectCache is no longer supported and must be true, due to
68 MediaWiki\Session\SessionManager. $wgSessionHandler is similarly no longer
69 used.
70 ** ObjectCacheSessionHandler is removed, replaced with
71 MediaWiki\Session\PhpSessionHandler.
72 ** PHP session handling in general ($_SESSION, session_id(), and so on) is
73 deprecated. Use MediaWiki\Session\SessionManager instead. A new config
74 variable, $wgPHPSessionHandling, is available to cause use of $_SESSION to
75 issue a deprecation warning or to cause most PHP session handling to throw
76 exceptions.
77 ** Deprecated UserSetCookies hook. Session-handling extensions should generally
78 be creating a custom subclass of CookieSessionProvider. Other extensions
79 messing with cookies can no longer count on user data being saved in cookies
80 versus other methods.
81 ** Deprecated UserLoadFromSession hook, extensions should create a
82 MediaWiki\Session\SessionProvider.
83 ** The User cannot be loaded from session until after Setup.php completes.
84 Attempts to do so will be ignored and the User will remain unloaded.
85 ** CSRF tokens may be fetched from the MediaWiki\Session\Session, which uses
86 the MediaWiki\Session\Token class.
87 * MediaWiki will now auto-create users as necessary, removing the need for
88 extensions to do so. An 'autocreateaccount' right is added to allow
89 auto-creation when 'createaccount' is not granted to all users.
90 * Deprecated AuthPluginAutoCreate hook in favor of LocalUserCreated.
91 * Most cookie-handling methods in User are deprecated.
92 * $wgAllowAsyncCopyUploads and $CopyUploadAsyncTimeout were removed. This was an
93 experimental feature that has never worked.
94 * Login and createaccount tokens now vary by timestamp.
95 * LoginForm::getLoginToken() and LoginForm::getCreateaccountToken()
96 return a MediaWiki\Session\Token, and tokens must be checked using that
97 class's methods.
98 * $wgEnotifUseJobQ was removed and the job queue is always used.
99 * The functionality of the ApiSandbox extension has been merged into core. The
100 extension should no longer be used.
101 * $wgPreloadJavaScriptMwUtil was removed (deprecated in 1.26).
102 Extensions, skins, gadgets and scripts that use the mediawiki.util module must
103 express a dependency on it.
104
105 === New features in 1.27 ===
106 * $wgDataCenterUpdateStickTTL was also added. This decides how long a user
107 sticks to the primary DC (via cookies) after they make changes to the site.
108 * Added a new hook, 'UserMailerTransformContent', to transform the contents
109 of an email. This is similar to the EmailUser hook but applies to all mail
110 sent via UserMailer.
111 * Added a new hook, 'UserMailerTransformMessage', to transform the contents
112 of an emai after MIME encoding.
113 * Added a new hook, 'UserMailerSplitTo', to control which users have to be
114 emailed separately (ie. there is a single address in the To: field) so
115 user-specific changes to the email can be applied safely.
116 * $wgCdnMaxageLagged was added, which limits the CDN cache TTL
117 when any load balancer uses a DB that is lagged beyond the 'max lag'
118 setting in the relevant section of $wgLBFactoryConf.
119 * User::newSystemUser() may be used to simplify the creation of passwordless
120 "system" users for logged actions from scripts and extensions.
121 * Extensions can now return detailed error information via the API when
122 preventing user actions using 'getUserPermissionsErrors' and similar hooks
123 by using ApiMessage instances instead of strings for the $result value.
124 * $wgAPIMaxLagThreshold was added to limit bot changes when databases lag
125 becomes too high.
126 * Skins and extensions can now use FlexBox mixins (.flex-display(@display: flex)
127 and .flex(@grow: 1, @shrink: 1, @width: auto, @order: 1)) in Less to create
128 cross-browser-compatible FlexBox rules. Users will still need to add fallback
129 float rules or the like for compatibility with IE9- separately.
130 * Added MWTimestamp::getTimezoneString() which returns the localized timezone
131 string, if available. To localize this string, see the comments of
132 $wgLocaltimezone in includes/DefaultSettings.php.
133 * Added CentralIdLookup, a service that allows extensions needing a concept of
134 "central" users to get that without having to know about specific central
135 authentication extensions.
136 * $wgMaxUserDBWriteDuration added to limit huge user-generated transactions.
137 Regular web request transactions that takes longer than this are aborted.
138 * Added a new hook, 'TitleMoveCompleting', which runs before a page move is
139 committed.
140 * $wgCdnReboundPurgeDelay was added to provide secondary delayed purges of URLs
141 from CDN to mitigate DB replication lag and WAN cache purge lag.
142 * (T49162) Installer will default to setting CACHE_ACCEL as the main cache type
143 if it is available.
144 * It is now possible to patrol file uploads (both for new files and new versions
145 of existing files). Special:NewFiles has gained an option to filter by patrol
146 status. This functionality can be disabled using $wgUseFilePatrol.
147 * MediaWiki\Session infrastructure allows for easier use of session mechanisms
148 other than the usual cookies.
149 ** SessionMetadata and SessionCheckInfo hooks allow for setting and checking
150 custom session metadata.
151 * Added MWGrants and associated configuration settings $wgGrantPermissions and
152 $wgGrantPermissionGroups to hold configuration for authentication features
153 such as OAuth that want to allow restricting the user rights a user may make
154 use of.
155 ** If you're already using the OAuth extension, these new variables are
156 identical to (and will replace) $wgMWOAuthGrantPermissions and
157 $wgMWOAuthGrantPermissionGroups.
158 * Added MWRestrictions as a class to check restrictions on a WebRequest, e.g.
159 to assert that the request comes from a particular IP range.
160 * Added bot passwords, a rights-restricted login mechanism for API-using bots.
161 * Whitelisted the following HTML attributes for all elements in wikitext:
162 aria-describedby, aria-flowto, aria-label, aria-labelledby, aria-owns.
163 * Removed "presentation" restriction on the HTML role attribute in wikitext.
164 All values are now allowed for the role attribute.
165 * $wgContentHandlers now also supports callbacks to create an instance of the
166 appropriate ContentHandler subclass.
167 * Added $wgAuthenticationTokenVersion, which if non-null prevents the
168 user_token database field from being exposed in cookies. Setting this would
169 be a good idea, but will log out all current sessions.
170 * $wgEventRelayerConfig was added, for managing PubSub event relay configuration,
171 specifically for reliable CDN url purges.
172
173 === External library changes in 1.27 ===
174
175 ==== Upgraded external libraries ====
176 * Updated oojs/oojs-ui from v0.12.12 to v0.13.3.
177 * Updated composer/semver from v1.0.0 to v1.2.0.
178 * Updated liuggio/statsd-php-client to 1.0.18.
179 * Updated QUnit from v1.18.0 to v1.22.0.
180
181 ==== New external libraries ====
182 * Added wikimedia/base-convert v1.0.1.
183 * Added wikimedia/cldr-plural-rule-parser v1.0.0.
184 * Added wikimedia/relpath v1.0.3.
185 * Added wikimedia/running-stat v1.1.0.
186 * Added wikimedia/php-session-serializer v1.0.3.
187
188 ==== Removed and replaced external libraries ====
189
190 === Bug fixes in 1.27 ===
191 * Special:Upload will now display correct maximum allowed file size when running
192 under HHVM (T116347).
193
194 === Action API changes in 1.27 ===
195 * Added list=allrevisions.
196 * generator=recentchanges now has the option to generate revids.
197 * ApiPageSet::setRedirectMergePolicy() was added. This allows generator
198 modules to define how generator data for a redirect source gets merged
199 into the redirect destination.
200 * prop=imageinfo&iiprop=uploadwarning will no longer include the possibility of
201 "was-deleted" warning.
202 * Added difftotextpst to query=revisions which preforms a pre-save transform on
203 the text before diffing it.
204 * Deprecated formats dbg, txt, and yaml have been removed.
205 * (T47988) The protect log event details now use new-style formatting.
206 * The following response properties from action=login are deprecated, and may
207 be removed in the future: lgtoken, cookieprefix, sessionid. Clients should
208 handle cookies to properly manage session state.
209 * action=login transparently allows login using bot passwords. Clients should
210 merely need to change the username and password used after setting up a bot
211 password.
212 * action=upload no longer understands statuskey, asyncdownload or leavemessage.
213
214 === Action API internal changes in 1.27 ===
215 * ApiQueryORM removed.
216 * The following classes have been removed:
217 ** ApiFormatDbg
218 ** ApiFormatTxt
219 ** ApiFormatYaml
220 * ApiBase::addTokenProperties() was removed (deprecated since 1.24).
221 * ApiBase::getFinalPossibleErrors() was removed (deprecated since 1.24).
222 * ApiBase::getFinalResultProperties() was removed (deprecated since 1.24).
223 * ApiBase::getRequireAtLeastOneParameterErrorMessages() was removed (deprecated since 1.24).
224 * ApiBase::getPossibleErrors() was removed (deprecated since 1.24).
225 * ApiBase::getRequireMaxOneParameterErrorMessages() was removed (deprecated since 1.24).
226 * ApiBase::getRequireOnlyOneParameterErrorMessages() was removed (deprecated since 1.24).
227 * ApiBase::getResultProperties() was removed (deprecated since 1.24).
228 * ApiBase::getTitleOrPageIdErrorMessage() was removed (deprecated since 1.24).
229 * ApiBase::parseErrors() was removed (deprecated since 1.24).
230 * ApiQueryBase::titleToKey(), ApiQueryBase::keyToTitle() and
231 ApiQueryBase::keyPartToTitle() all removed (deprecated since 1.24).
232 * ApiQueryBase::checkRowCount() was removed (deprecated since 1.24).
233 * ApiQueryBase::getDirectionDescription() was removed (deprecated since 1.25).
234 * ApiQuery::getGenerators() was removed (deprecated since 1.21).
235 * ApiQuery::getModules() was removed (deprecated since 1.21).
236 * ApiQuery::getModuleType() was removed (deprecated since 1.21).
237 * ApiQuery::setGeneratorContinue() was removed (deprecated since 1.24).
238 * ApiMain::getModules() was removed (deprecated since 1.21).
239 * ApiBase::getVersion() was removed (deprecated since 1.21).
240 * Language::getLangObj() was removed (deprecated since 1.24).
241 * Language::getLanguageName() was removed (deprecated since 1.20).
242 * Language::getLanguageNames() was removed (deprecated since 1.20).
243 * Language::getTranslatedLanguageNames() was removed (deprecated since 1.20).
244 * Language::specialPage() was removed (deprecated since 1.24).
245 * OutputPage::getHeadItems() was removed (deprecated since 1.24).
246 * OutputPage::getScript() was removed (deprecated since 1.24).
247 * OutputPage::out() was removed (deprecated since 1.22).
248 * OutputPage::setAllowedModules() was removed (deprecated since 1.24).
249
250 === Languages updated in 1.27 ===
251
252 MediaWiki supports over 350 languages. Many localisations are updated
253 regularly. Below only new and removed languages are listed, as well as
254 changes to languages because of Phabricator reports.
255
256 * (T113688) Change default numerals from Gurmukhi to Arabic for Punjabi locale.
257
258 === Other changes in 1.27 ===
259 * ProfilerOutputUdp was removed. Note that there is a ProfilerOutputStats class.
260 * WikiPage::doDeleteArticleReal() and WikiPage::doDeleteArticle() now
261 ignore the 2nd and 3rd arguments (formerly $id and $commit).
262 * Removed "loaderScripts" option from ResourceLoaderFileModule class.
263 * Removed ORM-like wrapper added in 1.20.
264 * LinkCache::getGoodLinks and LinkCache::getBadLinks were removed
265 (deprecated in 1.26).
266 * WikiPage::doQuickEdit() was removed (deprecated since 1.21).
267 * Removed SiteObject and SiteArray classes (deprecated in 1.21).
268 * MessageBlobStore::getInstance() was removed (deprecated since 1.25).
269 * (T84937) Free external links ("autolinked" urls) will now be terminated
270 by &nbsp; and HTML entity encodings of &nbsp, <, and >.
271 * (T36948) The default file revert message's timestamp is now in
272 $wgLocaltimezone, instead of UTC.
273 * The default name of the 'suppress' group page has been changed from
274 'Project:Oversight' to 'Project:Suppress'.
275 * DatabaseBase::resultObject() is now protected (use outside Database classes
276 not necessary since 1.11).
277 * Calling ResourceLoaderFileModule::readStyleFiles() without a
278 ResourceLoaderContext instance is deprecated.
279 * ResourceLoader::getLessCompiler() now takes an optional parameter of
280 additional LESS variables to set for the compiler.
281 * wfBaseConvert() marked as deprecated, use Wikimedia\base_convert() directly
282 instead.
283 * Obsolete maintenance scripts clearCacheStats.php and showCacheStats.php
284 were removed. The underlying data is sent to StatsD (see $wgStatsdServer).
285 * Removed msg_resource_links database table and associated code.
286 * Removed msg_resource database table and associated code.
287 * Skin::getNamespaceNotice() was removed.
288 * wfIsConfiguredProxy() was removed (deprecated since 1.24).
289 * wfDebugTimer() was removed (deprecated since 1.25).
290 * wfIsTrustedProxy() was removed (deprecated since 1.24).
291 * wfGetIP() was removed (deprecated since 1.19).
292 * MWHookException was removed.
293 * OutputPage::appendSubtitle() was removed (deprecated since 1.19).
294 * OutputPage::loginToUse() was removed (deprecated since 1.19).
295 * Article::loadContent() was removed (deprecated since 1.19).
296 * User::editToken() was removed (deprecated since 1.19).
297 * Removed --force-normal option of dumpBackup.php, as it no longer served
298 any useful purpose since 1.22.
299 * The functions processOption() and processArgs() on the BackupDumper and
300 TextPassDumper classes have been removed.
301 * The maintenance/backupTextPass.inc file was deleted. You should include
302 maintenance/dumpTextPass.php instead.
303 * WikiPage::getUsedTemplates() was removed (deprecated since 1.19).
304 * wfEmptyMsg() was removed (deprecated since 1.18).
305 * OutputPage::permissionRequired() was removed (deprecated since 1.18).
306 * OutputPage::blockedPage() was removed (deprecated since 1.18).
307 * User::getSkin() was removed (deprecated since 1.18).
308 * OutputPage::includeJQuery() was removed (deprecated since 1.17).
309 * WikiPage::updateRestrictions() was removed (deprecated since 1.19).
310 * WikiPage::testPreSaveTransform() was removed (deprecated since 1.19).
311 * LogPage::logName() was removed (deprecated since 1.19).
312 * LogPage::logHeader() was removed (deprecated since 1.19).
313 * wfCheckLimits() was removed (deprecated since 1.24).
314 * Linker::makeKnownLinkObj() was removed (deprecated since 1.16).
315 * Linker::makeLinkObj() was removed (deprecated since 1.16).
316 * wfMsgForContentNoTrans() was removed (deprecated since 1.18).
317 * ChangesList::usePatrol was removed (deprecated since 1.22).
318 * wfMsgNoTrans() was removed (deprecated since 1.18).
319 * Linker::makeImageLink2 was removed (deprecated since 1.20).
320 * Title::userIsWatching() was removed (deprecated since 1.20).
321 * Removed WaitForSlave maintenance script; use SELECT MASTER_POS_WAIT()
322 database function directly instead.
323 * wfMsg() was removed (deprecated since 1.18).
324 * wfMsgForContent() was removed (deprecated since 1.18).
325 * wfMsgReal() was removed (deprecated since 1.18).
326 * wfMsgGetKey() was removed (deprecated since 1.18).
327 * wfMsgHtml() was removed (deprecated since 1.18).
328 * wfMsgWikiHtml() was removed (deprecated since 1.18).
329 * wfMsgExt() was removed (deprecated since 1.18).
330 * Language::armourMath() was removed (deprecated since 1.22).
331 * LanguageConverter::armourMath() was removed (deprecated since 1.22).
332 * FakeConverter::armourMath() was removed (deprecated since 1.22).
333 * The unused jquery.validate ResourceLoader module was removed.
334 * FileRepo::getRootUrl() was removed (deprecated since 1.20).
335 * User::generateToken() was removed (deprecated since 1.20).
336 * WikiPage::getRawText() was removed (deprecated since 1.21).
337 * ParserOutput::hasCustomDataUpdates() was removed (deprecated since 1.25).
338 * ParserOutput::addSecondaryDataUpdate() was removed (deprecated since 1.25).
339 * ParserOutput::getSecondaryDataUpdates() was removed (deprecated since 1.25).
340 * Gallery images with multiple caption pipes no longer concatenate them all
341 together but instead pick the final one, similar to image syntax.
342 * XML-like parser tags (such as <gallery>), when unclosed, will be left unparsed
343 rather than consume everything until the end of the page.
344 * New maintenance script resetUserEmail.php allows sysadmins to reset user emails in case
345 a user forgot password/account was stolen.
346 * wfCheckEntropy() was removed (deprecated in 1.27).
347 * Browser support for Internet Explorer 8 lowered from Grade A to Grade C.
348 * ContentHandler::supportsCategories method added. Default is true.
349 CategoryMembershipChangeJob updates are skipped for content that
350 does not support categories.
351 * wikidiff difference engine is no longer supported, anyone still using it are encouraged
352 to upgrade to wikidiff2 which is actively maintained and has better package availability.
353 * Database logic was removed from WatchedItem and a WatchedItemStore was created:
354 ** WatchedItem::IGNORE_USER_RIGHTS and WatchedItem::CHECK_USER_RIGHTS were deprecated.
355 User::IGNORE_USER_RIGHTS and User::CHECK_USER_RIGHTS were introduced.
356 ** WatchedItem::fromUserTitle was deprecated in favour of the constructor.
357 ** WatchedItem::resetNotificationTimestamp was deprecated.
358 ** WatchedItem::batchAddWatch was deprecated.
359 ** WatchedItem::addWatch was deprecated.
360 ** WatchedItem::removeWatch was deprecated.
361 ** WatchedItem::isWatched was deprecated.
362 ** WatchedItem::duplicateEntries was deprecated.
363 ** EmailNotification::updateWatchlistTimestamp was deprecated.
364 ** User::getWatchedItem was removed.
365 * Unit tests don't work with external PHPUnit anymore, Composer is now the only supported
366 way. Run `composer install` to install it and other dev dependencies to run unit tests.
367 * wl_id field added to the watchlist table.
368
369 == Compatibility ==
370
371 MediaWiki 1.27 requires PHP 5.5.9 or later. There is experimental support for
372 HHVM 3.6.5 or later.
373
374 MySQL is the recommended DBMS. PostgreSQL or SQLite can also be used, but
375 support for them is somewhat less mature. There is experimental support for
376 Oracle and Microsoft SQL Server.
377
378 The supported versions are:
379
380 * MySQL 5.0.3 or later
381 * PostgreSQL 8.3 or later
382 * SQLite 3.3.7 or later
383 * Oracle 9.0.1 or later
384 * Microsoft SQL Server 2005 (9.00.1399)
385
386 == Upgrading ==
387
388 1.27 has several database changes since 1.26, and will not work without schema
389 updates. Note that due to changes to some very large tables like the revision
390 table, the schema update may take quite long (minutes on a medium sized site,
391 many hours on a large site).
392
393 If upgrading from before 1.11, and you are using a wiki as a commons
394 repository, make sure that it is updated as well. Otherwise, errors may arise
395 due to database schema changes.
396
397 If upgrading from before 1.7, you may want to run refreshLinks.php to ensure
398 new database fields are filled with data.
399
400 If you are upgrading from MediaWiki 1.4.x or earlier, you should upgrade to
401 1.5 first. The upgrade script maintenance/upgrade1_5.php has been removed
402 with MediaWiki 1.21.
403
404 Don't forget to always back up your database before upgrading!
405
406 See the file UPGRADE for more detailed upgrade instructions.
407
408 For notes on 1.26.x and older releases, see HISTORY.
409
410 == Online documentation ==
411
412 Documentation for both end-users and site administrators is available on
413 MediaWiki.org, and is covered under the GNU Free Documentation License (except
414 for pages that explicitly state that their contents are in the public domain):
415
416 https://www.mediawiki.org/wiki/Documentation
417
418 == Mailing list ==
419
420 A mailing list is available for MediaWiki user support and discussion:
421
422 https://lists.wikimedia.org/mailman/listinfo/mediawiki-l
423
424 A low-traffic announcements-only list is also available:
425
426 https://lists.wikimedia.org/mailman/listinfo/mediawiki-announce
427
428 It's highly recommended that you sign up for one of these lists if you're
429 going to run a public MediaWiki, so you can be notified of security fixes.
430
431 == IRC help ==
432
433 There's usually someone online in #mediawiki on irc.freenode.net.