Update HISTORY for 1.28.1/1.27.2/1.23.16
[lhc/web/wiklou.git] / RELEASE-NOTES-1.29
1 == MediaWiki 1.29 ==
2
3 THIS IS NOT A RELEASE YET
4
5 MediaWiki 1.29 is an alpha-quality branch and is not recommended for use in
6 production.
7
8 === Configuration changes in 1.29 ===
9 * Default cookie expiration time has been reduced to 30 days. Login cookie
10 expiration time is kept at 180 days.
11 * A new configuration variable has been added: $wgCookieSetOnAutoblock. This
12 determines whether to set a cookie when a user is autoblocked. Doing so means
13 that a blocked user, even after logging out and moving to a new IP address,
14 will still be blocked.
15 * The resetpassword right and associated password reset capture feature has
16 been removed.
17 * The $error parameter to the EmailUser hook should be set to a Status object
18 or boolean false. This should be compatible with at least MediaWiki 1.23 if
19 not earlier. Returning a raw HTML string is now deprecated.
20 * The $message parameter to the ApiCheckCanExecute hook should be set to an
21 ApiMessage. This is compatible with MediaWiki 1.27 and later. Returning a
22 code for ApiBase::parseMsg() will no longer work.
23 * ApiBase::$messageMap is no longer public. Code attempting to access it will
24 result in a PHP fatal error.
25 * $wgUserEmailUseReplyTo is now true by default to work around restrictive DMARC
26 policies.
27 * Subpages are now enabled by default in the Template namespace. Set
28 $wgNamespacesWithSubpages[NS_TEMPLATE] to false to keep the old behavior.
29 * $wgRunJobsAsync is now false by default (T142751). This change only affects
30 wikis with $wgJobRunRate > 0.
31 * A temporary feature flag, $wgDisableUserGroupExpiry, is provided to disable
32 new features that rely on the schema changes to the user_groups table. This
33 feature flag will likely be removed before 1.29 is released.
34 * (T158474) "Unknown user" has been added to $wgReservedUsernames.
35 * (T156983) $wgRateLimitsExcludedIPs now accepts CIDR ranges as well as single IPs.
36 * $wgDummyLanguageCodes is deprecated. Additional language code mappings may be
37 added to $wgExtraLanguageCodes instead.
38 * (T161453) LocalisationCache will no longer use the temporary directory in it's
39 fallback chain when trying to work out where to write the cache.
40
41 === New features in 1.29 ===
42 * (T5233) A cookie can now be set when a user is autoblocked, to track that user
43 if they move to a new IP address. This is disabled by default.
44 * Added ILocalizedException interface to standardize the use of localized
45 exceptions, largely so the API can handle them more sensibly.
46 * Blocks created automatically by MediaWiki, such as for configured proxies or
47 dnsbls, are now indicated as such and use a new i18n message when displayed.
48 * Added new $wgHTTPImportTimeout setting. Sets timeout for
49 downloading the XML dump during a transwiki import in seconds.
50 * Parser limit report is now available in machine-readable format to JavaScript
51 via mw.config.get('wgPageParseReport').
52 * Added $wgSoftBlockRanges, to allow for automatically blocking anonymous edits
53 from certain IP ranges (e.g. private IPs).
54 * (T59603) Added new magic word {{PAGELANGUAGE}} which returns the language code
55 of the page being parsed.
56 * HTML5 form validation attributes will no longer be suppressed. Originally
57 browsers had poor support for them, but modern browsers handle them fine.
58 This might affect some forms that used them and only worked because the
59 attributes were not actually being set.
60 * Expiry times can now be specified when users are added to user groups.
61 * Completely new user interface for the RecentChanges page, which
62 structures filters into user-friendly groups. This has corresponding
63 changes to how filters are registered by core and extensions.
64
65 === External library changes in 1.29 ===
66
67 ==== Upgraded external libraries ====
68 * Updated QUnit from v1.22.0 to v1.23.1.
69 * Updated cssjanus from v1.1.2 to v1.2.0.
70 * Updated psr/log from v1.0.0 to v1.0.2.
71 * Update Moment.js from v2.8.4 to v2.15.0.
72 * Updated oyejorge/less.php from v1.7.0.10 to v1.7.0.14.
73 * Updated monolog from v1.18.2 to 1.22.1.
74 * Updated wikimedia/composer-merge-plugin from v1.3.1 to v1.4.0.
75 * Updated OOjs from v1.1.10 to v2.0.0.
76
77 ==== New external libraries ====
78 * Added wikimedia/timestamp v1.0.0.
79 * Added wikimedia/remex-html v1.0.1.
80
81 ==== Removed and replaced external libraries ====
82
83 === Bug fixes in 1.29 ===
84 * (T62604) Core parser functions returning a number now format the number according
85 to the page content language, not wiki content language.
86 * (T27187) Search suggestions based on jquery.suggestions will now correctly only
87 highlight prefix matches in the results.
88 * (T157035) "new mw.Uri()" was ignoring options when using default URI.
89 * Special:Allpages can no longer be filtered by redirect in miser mode.
90 * (T160519) CACHE_ANYTHING will not be CACHE_ACCEL if no accelerator is installed.
91 * (T109140) (T122209) SECURITY: Special:UserLogin and Special:Search allow redirect
92 to interwiki links.
93 * (T144845) SECURITY: XSS in SearchHighlighter::highlightText() when
94 $wgAdvancedSearchHighlighting is true.
95 * (T125177) SECURITY: API parameters may now be marked as "sensitive" to keep
96 their values out of the logs.
97 * (T150044) SECURITY: "Mark all pages visited" on the watchlist now requires a CSRF
98 token.
99 * (T156184) SECURITY: Escape content model/format url parameter in message.
100 * (T151735) SECURITY: SVG filter evasion using default attribute values in DTD
101 declaration.
102 * (T161453) SECURITY: LocalisationCache will no longer use the temporary directory
103 in it's fallback chain when trying to work out where to write the cache.
104 * (T48143) SECURITY: Spam blacklist ineffective on encoded URLs inside file inclusion
105 syntax's link parameter.
106 * (T108138) SECURITY: Sysops can undelete pages, although the page is protected against
107 it.
108
109 === Action API changes in 1.29 ===
110 * Submitting sensitive authentication request parameters to action=login,
111 action=clientlogin, action=createaccount, action=linkaccount, and
112 action=changeauthenticationdata in the query string is now an error. They
113 should be submitted in the POST body instead.
114 * The capture option for action=resetpassword has been removed
115 * action=clearhasmsg now requires a POST.
116 * (T47843) API errors and warnings may be requested in non-English languages
117 using the new 'errorformat', 'errorlang', and 'errorsuselocal' parameters.
118 * API error codes may have changed. Most notably, errors from modules using
119 parameter prefixes (e.g. all query submodules) will no longer be prefixed.
120 * ApiPageSet-using modules will report the 'invalidreason' using the specified
121 'errorformat'.
122 * action=emailuser may return a "Warnings" status, and now returns 'warnings' and
123 'errors' subelements (as applicable) instead of 'message'.
124 * action=imagerotate returns an 'errors' subelement rather than 'errormessage'.
125 * action=move now reports errors when moving the talk page as an array under
126 key 'talkmove-errors', rather than using 'talkmove-error-code' and
127 'talkmove-error-info'. The format for subpage move errors has also changed.
128 * action=revisiondelete no longer includes a "rendered" property on warnings
129 and errors for each item. Use errorformat=wikitext if you're wanting parsed
130 output.
131 * action=rollback no longer returns a "messageHtml" property. Use
132 errorformat=html if you're wanting HTML formatting of error messages.
133 * action=upload now reports optional stash failures as an array under key
134 'stasherrors' rather than a 'stashfailed' text string.
135 * action=watch reports 'errors' and 'warnings' instead of a single 'error', and
136 no longer returns a 'message' on success.
137 * Added action=validatepassword to validate passwords for the account creation
138 and password change forms.
139 * action=purge now requires a POST.
140 * There is a new `languagevariants` siprop for action=query&meta=siteinfo,
141 which returns a list of languages with active LanguageConverter instances.
142 * action=query&query=allpages will no longer filter redirects using a database
143 query in miser mode. This may result in less results being returned than were
144 requested.
145
146 === Action API internal changes in 1.29 ===
147 * New methods were added to ApiBase to handle errors and warnings using i18n
148 keys. Methods for using hard-coded English messages were deprecated:
149 * ApiBase::dieUsage() was deprecated
150 * ApiBase::dieUsageMsg() was deprecated
151 * ApiBase::dieUsageMsgOrDebug() was deprecated
152 * ApiBase::getErrorFromStatus() was deprecated
153 * ApiBase::parseMsg() was deprecated
154 * ApiBase::setWarning() was deprecated
155 * ApiBase::$messageMap is no longer public. Code attempting to access it will
156 result in a PHP fatal error.
157 * The $message parameter to the ApiCheckCanExecute hook should be set to an
158 ApiMessage. This is compatible with MediaWiki 1.27 and later. Returning a
159 code for ApiBase::parseMsg() will no longer work.
160 * UsageException is deprecated in favor of ApiUsageException. For the time
161 being ApiUsageException is a subclass of UsageException to allow things that
162 catch only UsageException to still function properly.
163 * If, for some strange reason, code was using an ApiErrorFormatter instead of
164 ApiErrorFormatter_BackCompat, note that the result format has changed and
165 various methods now take a module path rather than a module name.
166 * ApiMessageTrait::getApiCode() now strips 'apierror-' and 'apiwarn-' prefixes
167 from the message key, and maps some message keys for backwards compatibility.
168 * API parameters may now be marked as "sensitive" to keep their values out of
169 the logs.
170
171 === Languages updated in 1.29 ===
172
173 MediaWiki supports over 350 languages. Many localisations are updated
174 regularly. Below only new and removed languages are listed, as well as
175 changes to languages because of Phabricator reports.
176
177 * Based as always on linguistic studies on intelligibility and language
178 knowledge by geography, language fallbacks have been expanded. When a
179 translation is missing in the user's preferred interface language, the
180 corresponding translation for the fallback language will be used instead.
181 English will only be used as last resort when there are no translations.
182 Some configurations (such as date formats and gender namespaces) have also
183 been updated when using the fallback language's configuration was inadequate.
184 The new or reinstated language fallbacks are (after cs ↔ sk in 1.28):
185 ca ↔ oc; hsb ↔ dsb; io → eo; mdf → ru; pnt → el; roa-tara → it; rup → ro;
186 sh → bs, sr-el, hr.
187 * (T137376) New language support: Atikamekw (atj).
188 * (T155957) Talk Namespaces for Javanese language (jv) have been updated.
189
190 ==== No fallback for Ukrainian ====
191 * (T39314) The fallback from Ukrainian to Russian was removed. The Ukrainian
192 language will now use the default fallback language: English. When a translation
193 to Ukrainian is not available, an English string will be shown.
194
195 === Other changes in 1.29 ===
196 * Database::getSearchEngine() (deprecated in 1.28) was removed. Use
197 SearchEngineFactory::getSearchEngineClass() instead.
198 * $wgSessionsInMemcached (deprecated in 1.20) was removed. No replacement is
199 required as all sessions are stored in Object Cache now.
200 * MWHttpRequest::execute() should be considered to return a StatusValue; the
201 Status return type is deprecated.
202 * User::edits() (deprecated in 1.21) was removed.
203 * Xml::escapeJsString() (deprecated in 1.21) was removed.
204 * Article::getText() and Article::prepareTextForEdit() (deprecated in 1.21)
205 were removed.
206 * Article::getAutosummary() and WikiPage::getAutosummary() (deprecated in 1.21)
207 were removed.
208 * Hook ArticleViewCustom (deprecated in 1.21) was removed. Use ArticleContentViewCustom
209 instead.
210 * Hooks EditPageGetDiffText and ShowRawCssJs (deprecated in 1.21) were removed.
211 * Class RevisiondeleteAction (deprecated in 1.25) was removed.
212 * WikiPage::prepareTextForEdit() (deprecated in 1.21) was removed.
213 * WikiPage::getText() (deprecated in 1.21) was removed.
214 * Article::fetchContent() (deprecated in 1.21) was removed.
215 * User::getPassword() (deprecated in 1.27) was removed.
216 * User::getTemporaryPassword() (deprecated in 1.27) was removed.
217 * User::isPasswordReminderThrottled() (deprecated in 1.27) was removed.
218 * Class FSRepo (deprecated in 1.19) was removed.
219 * WebRequest::checkSessionCookie() (deprecated in 1.27) was removed. Use
220 \MediaWiki\Session\SessionManager::singleton()->getPersistedSessionId() instead.
221 * Class ImageGallery (deprecated in 1.22) was removed.
222 Use ImageGalleryBase::factory instead.
223 * Title::moveNoAuth() (deprecated in 1.25) was removed. Use MovePage class instead.
224 * Hook UnknownAction (deprecated in 1.19) was actually deprecated (it will now
225 emit warnings). Create a subclass of Action and add it to $wgActions instead.
226 * WikiRevision::getText() (deprecated since 1.21) is no longer marked deprecated.
227 * Linker::getInterwikiLinkAttributes() (deprecated since 1.25) was removed.
228 * Linker::getInternalLinkAttributes() (deprecated since 1.25) was removed.
229 * Linker::getInternalLinkAttributesObj() (deprecated since 1.25) was removed.
230 * Linker::getLinkAttributesInternal() (deprecated since 1.25) was removed.
231 * RedisConnectionPool::handleException (deprecated since 1.23) was removed.
232 * The static properties mw.Api.errors and mw.Api.warnings, containing incomplete
233 and outdated lists of errors/warnings returned by the API, are now deprecated.
234 * wiki.phtml entry point was removed. Refer to index.php instead. If you want "wiki.phtml"
235 URLs to continue to work, set up redirects. In Apache, this can be done by enabling
236 mod_rewrite and adding the following rules to your configuration:
237
238 RewriteEngine On
239 RewriteBase /
240 RewriteRule ^/w/wiki\.phtml$ /w/index.php [R=301,L]
241 * Hook ArticleAfterFetchContent (deprecated in 1.21) was removed.
242 Use ArticleAfterFetchContentObject instead.
243 * Hook ArticleInsertComplete (deprecated in 1.21) was removed.
244 Use PageContentInsertComplete instead.
245 * Hook ArticleSave (deprecated in 1.21) was removed.
246 Use PageContentSave instead.
247 * Hook ArticleSaveComplete (deprecated in 1.21) was removed.
248 Use PageContentSaveComplete instead.
249 * Hook EditFilterMerged (deprecated in 1.21) was removed.
250 Use EditFilterMergedContent instead.
251 * Hook EditPageGetPreviewText (deprecated in 1.21) was removed.
252 Use EditPageGetPreviewContent instead.
253 * Hook TitleIsCssOrJsPage (deprecated in 1.21) was removed.
254 Use ContentHandlerDefaultModelFor instead.
255 * Hook TitleIsWikitextPage (deprecated in 1.21) was removed.
256 Use ContentHandlerDefaultModelFor instead.
257 * Article::getContent() (deprecated in 1.21) was removed.
258 * Revision::getText() (deprecated in 1.21) was removed.
259 * Article::doEdit() and WikiPage::doEdit() (deprecated in 1.21) were removed.
260 * Parser::replaceUnusualEscapes() (deprecated in 1.24) was removed.
261 * Article::doEditContent() was marked as deprecated, to be removed in 1.30
262 or later.
263 * ContentHandler::runLegacyHooks() was removed.
264 * refreshLinks.php now can be limited to a particular category with --category=...
265 or a tracking category with --tracking-category=...
266 * User-like objects that are passed to SpecialUserRights and its subclasses are
267 now required to have a getGroupMemberships() method. See UserRightsProxy for
268 an example.
269 * User::$mGroups (instance variable) was marked private. Use User::getGroups()
270 instead.
271 * User::getGroupName(), User::getGroupMember(), User:getGroupPage(),
272 User::makeGroupLinkHTML(), and User::makeGroupLinkWiki() were deprecated.
273 Use equivalent methods on the UserGroupMembership class.
274 * Maintenance scripts and tests that call User::addGroup() must now ensure that
275 User objects have been added to the database prior to calling addGroup().
276 * Protected function UsersPager::getGroups() was removed, and protected function
277 UsersPager::buildGroupLink() was changed from a static to an instance method.
278 * The third parameter ($cache) to the UsersPagerDoBatchLookups hook was changed;
279 see docs/hooks.txt.
280 * User::crypt() (deprecated in 1.24) was removed.
281 * User::comparePasswords() (deprecated in 1.24) was removed.
282 * ArchivedFile::getUserText() (deprecated in 1.23) was removed.
283 * HTMLFileCache::newFromTitle() (deprecated in 1.24) was removed.
284 * BREAKING CHANGE: Internal signature changes to ChangesListSpecialPage
285 and subclasses. It should only break if you call buildMainQueryConds
286 (changed to buildQuery with new signature) or doMainQuery (new
287 signature). Subclasses are likely to call at least doMainQuery
288 (possibly both), but other classes might too, because they were
289 public.
290 Also, some related hooks were deprecated, but this is not yet a
291 breaking change.
292 * Removed 'jquery.arrowSteps' module. (deprecated since 1.28)
293 * The 'jquery.autoEllipsis' ResourceLoader module is now deprecated.
294 * WikiRevision::$fileIsTemp was deprecated.
295 * WikiRevision::$importer was deprecated.
296 * WikiRevision::$user was deprecated.
297 * Article::getLastPurgeTimestamp(), WikiPage::getLastPurgeTimestamp(), and the
298 WikiPage::PURGE_* constants are deprecated, and the functions will always
299 return false. They were a hack for an issue that has since been fixed.
300 * Hook 'EditPageBeforeEditChecks' is now deprecated. Instead use the new hook
301 'EditPageGetCheckboxesDefinition', or 'EditPage::showStandardInputs:options'
302 if you don't actually care about checkboxes and just want to add some HTML
303 to the page.
304 * Selflinks are now rendered as href-less <a> tags with the class mw-selflink
305 rather than <strong> tags. The old class name, "selflink", was deprecated
306 and will be removed in a future release. (T160480)
307 * (T156184) $wgRawHtml will no longer apply to internationalization messages.
308 * Browser support for non-ES5 JavaScript browsers, including Android 2,
309 Opera <12.10, and Internet Explorer 9, was lowered from Grade A to Grade C.
310
311 == Compatibility ==
312
313 MediaWiki 1.29 requires PHP 5.5.9 or later. There is experimental support for
314 HHVM 3.6.5 or later.
315
316 MySQL is the recommended DBMS. PostgreSQL or SQLite can also be used, but
317 support for them is somewhat less mature. There is experimental support for
318 Oracle and Microsoft SQL Server.
319
320 The supported versions are:
321
322 * MySQL 5.0.3 or later
323 * PostgreSQL 8.3 or later
324 * SQLite 3.3.7 or later
325 * Oracle 9.0.1 or later
326 * Microsoft SQL Server 2005 (9.00.1399)
327
328 == Upgrading ==
329
330 1.29 has several database changes since 1.28, and will not work without schema
331 updates. Note that due to changes to some very large tables like the revision
332 table, the schema update may take quite long (minutes on a medium sized site,
333 many hours on a large site).
334
335 If upgrading from before 1.11, and you are using a wiki as a commons
336 repository, make sure that it is updated as well. Otherwise, errors may arise
337 due to database schema changes.
338
339 If upgrading from before 1.7, you may want to run refreshLinks.php to ensure
340 new database fields are filled with data.
341
342 If you are upgrading from MediaWiki 1.4.x or earlier, you should upgrade to
343 1.5 first. The upgrade script maintenance/upgrade1_5.php has been removed
344 with MediaWiki 1.21.
345
346 Don't forget to always back up your database before upgrading!
347
348 See the file UPGRADE for more detailed upgrade instructions.
349
350 For notes on 1.28.x and older releases, see HISTORY.
351
352 == Online documentation ==
353
354 Documentation for both end-users and site administrators is available on
355 MediaWiki.org, and is covered under the GNU Free Documentation License (except
356 for pages that explicitly state that their contents are in the public domain):
357
358 https://www.mediawiki.org/wiki/Special:MyLanguage/Documentation
359
360 == Mailing list ==
361
362 A mailing list is available for MediaWiki user support and discussion:
363
364 https://lists.wikimedia.org/mailman/listinfo/mediawiki-l
365
366 A low-traffic announcements-only list is also available:
367
368 https://lists.wikimedia.org/mailman/listinfo/mediawiki-announce
369
370 It's highly recommended that you sign up for one of these lists if you're
371 going to run a public MediaWiki, so you can be notified of security fixes.
372
373 == IRC help ==
374
375 There's usually someone online in #mediawiki on irc.freenode.net.