Add support for blacklisting common passwords
[lhc/web/wiklou.git] / RELEASE-NOTES-1.27
1 Security reminder: If you have PHP's register_globals option set, you must
2 turn it off. MediaWiki will not work with it enabled.
3
4 == MediaWiki 1.27 ==
5
6 THIS IS NOT A RELEASE YET
7
8 MediaWiki 1.27 is an alpha-quality branch and is not recommended for use in
9 production.
10
11 === Configuration changes in 1.27 ===
12 * $wgUseLinkNamespaceDBFields was removed.
13 * Deprecated $wgResourceLoaderMinifierStatementsOnOwnLine and
14 $wgResourceLoaderMinifierMaxLineLength, because there was little value in
15 making the behavior configurable. The default values (`false` for the former,
16 1000 for the latter) are now hard-coded.
17 * $wgDebugDumpSqlLength was removed (deprecated in 1.24).
18 * $wgDebugDBTransactions was removed (deprecated in 1.20).
19 * $wgUseXVO has been removed, as it provides functionality only used by
20 custom Wikimedia patches against Squid 2.x that probably noone uses in
21 production anymore. There is now $wgUseKeyHeader that provides similar
22 functionality but instead of the MediaWiki-specific X-Vary-Options header,
23 uses the draft Key header standard.
24 * $wgScriptExtension (and support for '.php5' entry points) was removed. See the
25 deprecation notice in the release notes for version 1.25 for advice on how to
26 preserve support for '.php5' entry points via URL rewriting.
27 * Password handling via the User object has been deprecated and partially
28 removed, pending the future introduction of AuthManager. In particular:
29 ** expirePassword(), getPasswordExpireDate(), resetPasswordExpiration(), and
30 getPasswordExpired() have been removed. They were unused outside of core.
31 ** The mPassword, mNewpassword, mNewpassTime, and mPasswordExpires fields are
32 now private and will be removed in the future.
33 ** The getPassword() and getTemporaryPassword() methods now throw
34 BadMethodCallException and will be removed in the future.
35 ** The ability to pass 'password' and 'newpassword' to createNew() has been
36 removed. The only users of it seem to have been using it to set invalid
37 passwords, and so shouldn't be greatly affected.
38 ** setPassword(), setInternalPassword(), and setNewpassword() have been
39 deprecated, pending the introduction of AuthManager.
40 ** User::randomPassword() is deprecated in favor of a new method
41 PasswordFactory::generateRandomPasswordString()
42 ** User::getPasswordFactory() is deprecated, callers should just create a
43 PasswordFactory themselves.
44 ** A new constructor, User::newSystemUser(), has been added to simplify the
45 creation of passwordless "system" users for logged actions.
46 * $wgMaxSquidPurgeTitles was removed.
47 * $wgAjaxWatch was removed. This is now enabled by default.
48 * $wgUseInstantCommons now hotlinks Commons images by default instead of
49 downloading originals and thumbnailing them locally. This allows wikis to save
50 on CPU and bandwidth while reducing time to first byte for pages, even without
51 a thumbnail handler. See $wgForeignFileRepos documentation for tweaks.
52 * (T27397) WebP is enabled by default as an uploadable filetype.
53 * (T48998) $wgArticlePath must now be either a full url, or start with a "/".
54
55 === New features in 1.27 ===
56 * $wgDataCenterId and $wgDataCenterRoles where added, which will serve as
57 basic configuration settings needed for multi-datacenter setups.
58 $wgDataCenterUpdateStickTTL was also added.
59 * Added a new hook, 'UserMailerTransformContent', to transform the contents
60 of an email. This is similar to the EmailUser hook but applies to all mail
61 sent via UserMailer.
62 * Added a new hook, 'UserMailerTransformMessage', to transform the contents
63 of an emai after MIME encoding.
64 * Added a new hook, 'UserMailerSplitTo', to control which users have to be
65 emailed separately (ie. there is a single address in the To: field) so
66 user-specific changes to the email can be applied safely.
67 * $wgCdnMaxageLagged was added, which limits the CDN cache TTL
68 when any load balancer uses a DB that is lagged beyond the 'max lag'
69 setting in the relevant section of $wgLBFactoryConf.
70 * User::newSystemUser() may be used to simplify the creation of passwordless
71 "system" users for logged actions from scripts and extensions.
72 * Extensions can now return detailed error information via the API when
73 preventing user actions using 'getUserPermissionsErrors' and similar hooks
74 by using ApiMessage instances instead of strings for the $result value.
75 * $wgAPIMaxLagThreshold was added to limit bot changes when databases lag
76 becomes too high.
77 * Skins and extensions can now use FlexBox mixins (.flex-display(@display: flex)
78 and .flex(@grow: 1, @shrink: 1, @width: auto, @order: 1)) in Less to create
79 cross-browser-compatible FlexBox rules. Users will still need to add fallback
80 float rules or the like for compatibility with IE9- separately.
81
82 ==== External libraries ====
83
84 === Bug fixes in 1.27 ===
85 * Special:Upload will now display correct maximum allowed file size when running
86 under HHVM (T116347).
87
88 === Action API changes in 1.27 ===
89 * Added list=allrevisions.
90 * generator=recentchanges now has the option to generate revids.
91 * ApiPageSet::setRedirectMergePolicy() was added. This allows generator
92 modules to define how generator data for a redirect source gets merged
93 into the redirect destination.
94 * prop=imageinfo&iiprop=uploadwarning will no longer include the possibility of
95 "was-deleted" warning.
96 * Added difftotextpst to query=revisions which preforms a pre-save transform on
97 the text before diffing it.
98
99 === Action API internal changes in 1.27 ===
100 * ApiQueryORM removed.
101
102 === Languages updated in 1.27 ===
103
104 MediaWiki supports over 350 languages. Many localisations are updated
105 regularly. Below only new and removed languages are listed, as well as
106 changes to languages because of Bugzilla reports.
107
108 * (T113688) Change default numerals from Gurmukhi to Arabic for Punjabi locale.
109
110 === Other changes in 1.27 ===
111 * ProfilerOutputUdp was removed. Note that there is a ProfilerOutputStats class.
112 * WikiPage::doDeleteArticleReal() and WikiPage::doDeleteArticle() now
113 ignore the 2nd and 3rd arguments (formerly $id and $commit).
114 * Removed "loaderScripts" option from ResourceLoaderFileModule class.
115 * Removed ORM-like wrapper added in 1.20.
116 * LinkCache::getGoodLinks and LinkCache::getBadLinks were removed (deprecated in 1.26).
117 * WikiPage::doQuickEdit() was removed (deprecated since 1.21).
118 * Removed SiteObject and SiteArray classes (deprecated in 1.21).
119 * MessageBlobStore::getInstance() was removed (deprecated since 1.25).
120
121 == Compatibility ==
122
123 MediaWiki 1.27 requires PHP 5.3.3 or later. There is experimental support for
124 HHVM 3.3.0.
125
126 MySQL is the recommended DBMS. PostgreSQL or SQLite can also be used, but
127 support for them is somewhat less mature. There is experimental support for
128 Oracle and Microsoft SQL Server.
129
130 The supported versions are:
131
132 * MySQL 5.0.3 or later
133 * PostgreSQL 8.3 or later
134 * SQLite 3.3.7 or later
135 * Oracle 9.0.1 or later
136 * Microsoft SQL Server 2005 (9.00.1399)
137
138 == Upgrading ==
139
140 1.27 has several database changes since 1.26, and will not work without schema
141 updates. Note that due to changes to some very large tables like the revision
142 table, the schema update may take quite long (minutes on a medium sized site,
143 many hours on a large site).
144
145 If upgrading from before 1.11, and you are using a wiki as a commons
146 repository, make sure that it is updated as well. Otherwise, errors may arise
147 due to database schema changes.
148
149 If upgrading from before 1.7, you may want to run refreshLinks.php to ensure
150 new database fields are filled with data.
151
152 If you are upgrading from MediaWiki 1.4.x or earlier, you should upgrade to
153 1.5 first. The upgrade script maintenance/upgrade1_5.php has been removed
154 with MediaWiki 1.21.
155
156 Don't forget to always back up your database before upgrading!
157
158 See the file UPGRADE for more detailed upgrade instructions.
159
160 For notes on 1.26.x and older releases, see HISTORY.
161
162 == Online documentation ==
163
164 Documentation for both end-users and site administrators is available on
165 MediaWiki.org, and is covered under the GNU Free Documentation License (except
166 for pages that explicitly state that their contents are in the public domain):
167
168 https://www.mediawiki.org/wiki/Documentation
169
170 == Mailing list ==
171
172 A mailing list is available for MediaWiki user support and discussion:
173
174 https://lists.wikimedia.org/mailman/listinfo/mediawiki-l
175
176 A low-traffic announcements-only list is also available:
177
178 https://lists.wikimedia.org/mailman/listinfo/mediawiki-announce
179
180 It's highly recommended that you sign up for one of these lists if you're
181 going to run a public MediaWiki, so you can be notified of security fixes.
182
183 == IRC help ==
184
185 There's usually someone online in #mediawiki on irc.freenode.net.