Merge "Make DatabaseMysqlBase use connLogger for connection errors"
[lhc/web/wiklou.git] / RELEASE-NOTES-1.28
1 == MediaWiki 1.28 ==
2
3 THIS IS NOT A RELEASE YET
4
5 MediaWiki 1.28 is an alpha-quality branch and is not recommended for use in
6 production.
7
8 === Configuration changes in 1.28 ===
9 * $wgSend404Code now affects status code of action=history if the page is not there.
10 * BREAKING CHANGE: $wgHTTPProxy is now *required* for all external requests
11 made by MediaWiki via a proxy. Relying on the http_proxy environment
12 variable is no longer supported.
13 * The load.php entry point now enforces the existing policy of not allowing
14 access to session data, which includes the session user and the session
15 user's language. If such access is attempted, an exception will be thrown.
16 * The number of internal PBKDF2 iterations used to derive the session secret
17 is configurable via $wgSessionPbkdf2Iterations.
18 * Upload dialog's file upload log comment can now be configured separately for
19 local and foreign uploads.
20 * $wgForeignUploadTargets now defaults to `[ 'local' ]`, where `'local'`
21 signifies local uploads. A value of `[]` (empty array) now means that
22 no upload targets are allowed, effectively disabling the upload dialog.
23 * The deprecated $wgEditEncoding variable has been removed; it was only used
24 for Esperanto language character conversion. You are now recommended to use
25 input methods provided by the UniversalLanguageSelector extension.
26 * When $wgPingback is true, MediaWiki will periodically ping
27 https://www.mediawiki.org/beacon with basic information about the local
28 MediaWiki installation. This data includes, for example, the type of system,
29 PHP version, and chosen database backend. This behavior is off by default.
30 * When $wgEditSubmitButtonLabelPublish is true, MediaWiki will label the button
31 to store-to-database-and-show-to-others as "Publish page"/"Publish changes";
32 if false, the default, they will be "Save page"/"Save changes".
33 * The 'editcontentmodel' permission is now granted to all logged-in users ('user').
34 instead of just administrators ('sysop'). Documentation for this feature is
35 available at <https://www.mediawiki.org/wiki/Help:ChangeContentModel>.
36 * $wgRevisionCacheExpiry is now set to one week by default instead of being disabled.
37
38 === New features in 1.28 ===
39 * User::isBot() method for checking if an account is a bot role account.
40 * Added a new 'slideshow' mode for galleries.
41 * Added a new hook, 'UserIsBot', to aid in determining if a user is a bot.
42 * Added a new hook, 'ApiMakeParserOptions', to allow extensions to better
43 interact with API parsing.
44 * Added a new hook, 'UploadVerifyUpload', which can be used to reject a file
45 upload. Unlike 'UploadVerifyFile' it provides information about upload comment
46 and the file description page, but does not run for uploads to stash.
47 * (T141604) Extensions can now provide a better error message when their
48 maintenance scripts are run without the extension being installed.
49 * (T8948) Numeric sorting in categories is now supported by setting $wgCategoryCollation
50 to 'uca-default-u-kn' or 'uca-<langcode>-u-kn'. If you can't use UCA collations,
51 a 'numeric' collation is also available. If migrating from another
52 collation, you will need to run the updateCollation.php maintenance script.
53 * Two new codes have been added to #time parser function: "xit" for days in current
54 month, and "xiz" for days passed in the year, both in Iranian calendar.
55 * mw.Api has a new option, useUS, to use U+001F (Unit Separator) when
56 appropriate for sending multi-valued parameters. This defaults to true when
57 the mw.Api instance seems to be for the local wiki.
58 * After a client performs an action which alters a database that has replica databases,
59 MediaWiki will wait for the replica databases to synchronize with the master database
60 while it renders the HTML output. However, if the output is a redirect to another wiki
61 on the wiki farm with a different domain, MediaWiki will instead alter the redirect
62 URL to include a ?cpPosTime parameter that triggers the database synchronization when
63 the URL is followed by the client. The same-domain case uses a new cpPosTime cookie.
64
65 === External library changes in 1.28 ===
66
67 ==== Upgraded external libraries ====
68 * Updated es5-shim from v4.1.5 to v4.5.8
69 * Updated composer/semver from v1.4.1 to v1.4.2
70 * Updated wikimedia/php-session-serializer from v1.0.3 to v1.0.4
71
72 ==== New external libraries ====
73 * Added wikimedia/scoped-callback v1.0.0
74 * Added wikimedia/wait-condition-loop v1.0.1
75
76 ==== Removed and replaced external libraries ====
77
78 === Bug fixes in 1.28 ===
79 * (T146496) action=history pages should return 404 HTTP error code if the page does not exist
80 * (T137264) SECURITY: XSS in unclosed internal links
81 * (T133147) SECURITY: Escape '<' and ']]>' in inline <style> blocks
82 * (T133147) SECURITY: Require login to preview user CSS pages
83 * (T132926) SECURITY: Do not allow undeleting a revision deleted file if it is
84 the top file
85 * (T129738) SECURITY: Make $wgBlockDisablesLogin also restrict logged in
86 permissions
87 * (T129738) SECURITY: Make blocks log users out if $wgBlockDisablesLogin is true
88 * (T139670) Move 'UserGetRights' call before application of
89 Session::getAllowedUserRights()
90
91 === Action API changes in 1.28 ===
92 * Added 'maxarticlesize' property to action=query&meta=siteinfo which contains
93 the value of $wgMaxArticleSize.
94 * Property 'modulemessages' from action=parse&prop=modules was removed
95 (deprecated since 1.26).
96 * The following response properties from action=login, deprecated in 1.27, are
97 now removed: lgtoken, cookieprefix, sessionid. Clients should handle cookies
98 to properly manage session state.
99 * Submitting the lgtoken and lgpassword parameters in the query string to
100 action=login is now deprecated and outputs a warning. They should be submitted
101 in the POST body instead.
102 * Submitting sensitive authentication request parameters to action=clientlogin,
103 action=createaccount, action=linkaccount, and action=changeauthenticationdata
104 in the query string is now deprecated and outputs a warning. They should be
105 submitted in the POST body instead.
106 * (T141960) Multi-valued parameters may now be separated using U+001F (Unit Separator)
107 instead of the pipe character. This will be useful if some of the multiple
108 values need to contain pipes, e.g. for action=options.
109 * The API will now warn if input is not NFC-normalized Unicode or if it
110 contains invalid characters.
111 * The 'normalized' list output by action=query and other modules that use
112 ApiPageSet may contain entries where the 'from' value is percent-encoded as
113 the raw value cannot be represented in a valid API response. These are
114 indicated by a 'fromencoded' boolean alongside the existing 'from' parameter.
115 * (T28680) action=paraminfo can now return info about all submodules of a
116 module without listing them all explicitly.
117 * (T146770) It is now possible to assert that the current user is a specific
118 named user, using the 'assertuser' parameter.
119
120 === Action API internal changes in 1.28 ===
121 * Added a new hook, 'ApiMakeParserOptions', to allow extensions to better
122 interact with ApiParse and ApiExpandTemplates.
123 * (T139565) SECURITY: API: Generate head items in the context of the given title
124 * (T115333) SECURITY: Check read permission when loading page content in ApiParse
125 * ApiBase::getResultData() was removed (deprecated since 1.25)
126 * ApiBase::makeHelpArrayToString() was removed (deprecated since 1.25)
127 * ApiBase::makeHelpMsgParameters() was removed (deprecated since 1.25)
128 * ApiBase::makeHelpMsg() was removed (deprecated since 1.25)
129 * ApiFormatBase::formatHTML() was removed (deprecated since 1.25)
130 * ApiFormatBase::getNeedsRawData() was removed (deprecated since 1.25)
131 * ApiFormatBase::getWantsHelp() was removed (deprecated since 1.25)
132 * ApiFormatBase::setBufferResult() was removed (deprecated since 1.25)
133 * ApiFormatBase::setHelp() was removed (deprecated since 1.25)
134 * ApiFormatBase::setUnescapeAmps() was removed (deprecated since 1.25)
135 * ApiMain::makeHelpMsgHeader() was removed (deprecated since 1.25)
136 * ApiMain::reallyMakeHelpMsg() was removed (deprecated since 1.25)
137 * ApiMain::setHelp() was removed (deprecated since 1.25)
138 * ApiResult::beginContinuation() was removed (deprecated since 1.25)
139 * ApiResult::cleanUpUTF8() was removed (deprecated since 1.25)
140 * ApiResult::convertStatusToArray() was removed (deprecated since 1.25)
141 * ApiResult::disableSizeCheck() was removed (deprecated since 1.24)
142 * ApiResult::enableSizeCheck() was removed (deprecated since 1.24)
143 * ApiResult::endContinuation() was removed (deprecated since 1.25)
144 * ApiResult::getData() was removed (deprecated since 1.25)
145 * ApiResult::getIsRawMode() was removed (deprecated since 1.25)
146 * ApiResult::setContent() was removed (deprecated since 1.25)
147 * ApiResult::setContinueParam() was removed (deprecated since 1.25)
148 * ApiResult::setElement() was removed (deprecated since 1.25)
149 * ApiResult::setGeneratorContinueParam() was removed (deprecated since 1.25)
150 * ApiResult::setIndexedTagName_internal() was removed (deprecated since 1.25)
151 * ApiResult::setIndexedTagName_recursive() was removed (deprecated since 1.25)
152 * ApiResult::setMainForContinuation() was removed (deprecated since 1.25)
153 * ApiResult::setParsedLimit() was removed (deprecated since 1.25)
154 * ApiResult::setRawMode() was removed (deprecated since 1.25)
155 * ApiResult::size() was removed (deprecated since 1.25)
156
157 === Languages updated in 1.28 ===
158
159 MediaWiki supports over 350 languages. Many localisations are updated
160 regularly. Below only new and removed languages are listed, as well as
161 changes to languages because of Phabricator reports.
162
163 * (T137411) ban (Balinese), thanks to translators Adi Mayndra, Andru,
164 BASAbali, M. Adiputra, Naval Scene, Nemo bis, NoiX180, and 아라.
165 * (T135867) shn (Shan), thanks to translators Khun Sar, Piangpha,
166 Saiddzone Saimawnkham, Saosukham, and Sengwan.
167 * Czech (cs) and Slovak (sk) set as reciprocal fallbacks
168
169 === Other changes in 1.28 ===
170 * (T128697) Improved handling of large diffs.
171 * [BREAKING CHANGE] $wgExtendedLoginCookies has been removed. You can
172 use or update a custom session provider if needed.
173 * Deprecated APIEditBeforeSave hook in favor of EditFilterMergedContent.
174 * The 'UploadVerification' hook is deprecated. Use 'UploadVerifyFile' instead.
175 * SiteConfiguration::isLocalVHost() was removed (deprecated since 1.25).
176 * The 'UserLoginComplete' hook has a new parameter to differentiate between actual
177 login and visiting the login page while already logged in.
178 * ResourceLoader::makeLoaderURL() was removed (deprecated since 1.24).
179 * $.fn.liveAndTestAtStart was removed (deprecated since 1.24).
180 * mw.util.tooltipAccessKeyPrefix was removed (deprecated since 1.24).
181 * mw.util.tooltipAccessKeyRegexp was removed (deprecated since 1.24).
182 * Linker::link() and Linker::linkKnown() were deprecated; please instead use
183 MediaWiki\Linker\LinkRenderer. In addition, the LinkBegin and LinkEnd hooks
184 were replaced by HtmlPageLinkRendererBegin and HtmlPageLinkRendererEnd
185 respectively. See docs/hooks.txt for the specific changes needed for those hooks.
186 * Linker::formatSize() was deprecated. Use Language::formatSize() directly.
187 * Aliases for Linker methods, deprecated since 1.21, were removed from Skin:
188 * Skin::commentBlock() (use Linker::commentBlock() instead)
189 * Skin::generateRollback() (use Linker::generateRollback() instead)
190 * Skin::link() (use MediaWiki\Linker\LinkRenderer instead)
191 * Skin::linkKnown() (use MediaWiki\Linker\LinkRenderer instead)
192 * Skin::userLink() (use Linker::userLink() instead)
193 * Skin::userToolLinks() (use Linker::userToolLinks() instead)
194 * The 'ParserLimitReportFormat' hook was removed.
195 * Disabled "bug 2702" HTML tidying of parsed UI messages on wikis where Tidy is
196 disabled.
197 * DifferenceEngine::generateDiffBody() was removed (deprecated since 1.21).
198 * UploadBase::stashFileGetKey() and UploadBase::stashSession() were deprecated.
199 Use ...->stashFile()->getFileKey() instead.
200 * "Public domain" was removed as a wiki license option from the installer, in
201 favour of CC-0.
202 * AuthenticationRequest::$required is now changed from REQUIRED to PRIMARY_REQUIRED
203 on requests needed by primary providers even if all primaries need them.
204 Primary providers are discouraged from returning multiple REQUIRED requests.
205 * OOjs UI PHP widgets constructed with the `'infusable' => true` config option
206 will no longer be automatically infused. You should call `OO.ui.infuse()`
207 on them yourself from your JavaScript code.
208 * parserTests.php has moved to tests/parser/parserTests.php
209 * The command line options specific to parser tests have been removed from
210 phpunit.php: --regex and --keep-uploads. Instead of --regex, use --filter.
211 Instead of --keep-uploads, use the same option to parserTests.php, but you
212 must specify a directory with --upload-dir.
213 * The 'jquery.arrowSteps' ResourceLoader module is now deprecated.
214 * IP::isConfiguredProxy() and IP::isTrustedProxy() were removed. Callers should
215 migrate to using the same functions on a ProxyLookup instance, obtainable from
216 MediaWikiServices.
217 * The ArticleAfterFetchContent, ArticleSave, ArticleViewCustom, EditPageGetDiffText,
218 EditPageGetPreviewText and ShowRawCssJs hooks will now emit deprecation warnings if
219 used.
220
221 == Compatibility ==
222
223 MediaWiki 1.28 requires PHP 5.5.9 or later. There is experimental support for
224 HHVM 3.6.5 or later.
225
226 MySQL is the recommended DBMS. PostgreSQL or SQLite can also be used, but
227 support for them is somewhat less mature. There is experimental support for
228 Oracle and Microsoft SQL Server.
229
230 The supported versions are:
231
232 * MySQL 5.0.3 or later
233 * PostgreSQL 8.3 or later
234 * SQLite 3.3.7 or later
235 * Oracle 9.0.1 or later
236 * Microsoft SQL Server 2005 (9.00.1399)
237
238 == Upgrading ==
239
240 1.28 has several database changes since 1.27, and will not work without schema
241 updates. Note that due to changes to some very large tables like the revision
242 table, the schema update may take quite long (minutes on a medium sized site,
243 many hours on a large site).
244
245 If upgrading from before 1.11, and you are using a wiki as a commons
246 repository, make sure that it is updated as well. Otherwise, errors may arise
247 due to database schema changes.
248
249 If upgrading from before 1.7, you may want to run refreshLinks.php to ensure
250 new database fields are filled with data.
251
252 If you are upgrading from MediaWiki 1.4.x or earlier, you should upgrade to
253 1.5 first. The upgrade script maintenance/upgrade1_5.php has been removed
254 with MediaWiki 1.21.
255
256 Don't forget to always back up your database before upgrading!
257
258 See the file UPGRADE for more detailed upgrade instructions.
259
260 For notes on 1.27.x and older releases, see HISTORY.
261
262 == Online documentation ==
263
264 Documentation for both end-users and site administrators is available on
265 MediaWiki.org, and is covered under the GNU Free Documentation License (except
266 for pages that explicitly state that their contents are in the public domain):
267
268 https://www.mediawiki.org/wiki/Special:MyLanguage/Documentation
269
270 == Mailing list ==
271
272 A mailing list is available for MediaWiki user support and discussion:
273
274 https://lists.wikimedia.org/mailman/listinfo/mediawiki-l
275
276 A low-traffic announcements-only list is also available:
277
278 https://lists.wikimedia.org/mailman/listinfo/mediawiki-announce
279
280 It's highly recommended that you sign up for one of these lists if you're
281 going to run a public MediaWiki, so you can be notified of security fixes.
282
283 == IRC help ==
284
285 There's usually someone online in #mediawiki on irc.freenode.net.