Add maintenance script for resetting login/signup throttle
[lhc/web/wiklou.git] / RELEASE-NOTES-1.32
1 == MediaWiki 1.32 ==
2
3 THIS IS NOT A RELEASE YET
4
5 MediaWiki 1.32 is an alpha-quality branch and is not recommended for use in
6 production.
7
8 === Configuration changes in 1.32 ===
9 * (T115414) The $wgEnableAPI and $wgEnableWriteAPI settings, deprecated in 1.31,
10 have been removed.
11 * The $wgUseAjax setting, deprecated in 1.31, is now ignored.
12 * The $wgSiteSupportPage setting, unused since 1.5, was removed.
13 * The $wgBrowserBlacklist setting, deprecated in 1.30, was removed.
14 * The default quality of JPEG thumbnails generated by GD was reduced from 95 to
15 80. The quality of JPEG thumbnails is now configurable through the new setting
16 $wgJpegQuality (default 80). This aligns the quality to what ImageMagick uses.
17 * $wgExperimentalHtmlIds, deprecated since 1.30, has been removed. The
18 'html5-legacy' value for $wgFragmentMode is no longer accepted.
19 * The experimental Html5Internal and Html5Depurate tidy drivers were removed.
20 RemexHtml, which is the default, should be used instead.
21 * (T135963) You can now define a Content Security Policy for your wiki. This
22 adds a defense-in-depth feature to stop an attacker who has found a bug in
23 the parser allowing them to insert malicious attributes. Disabled by default,
24 you can configure this via $wgCSPHeader and $wgCSPReportOnlyHeader.
25 * New configuration variable has been added: $wgCookieSetOnIpBlock.
26 This determines whether to set a cookie when an IP user is blocked. Doing so
27 means that a blocked user, even after moving to a new IP address, will still
28 be blocked.
29 * The archive table's ar_rev_id field is now unique.
30 * Special:BotPasswords now requires reauthentication.
31 * (T194414) The default watchlist view time has been increased from 3 to 7 days.
32
33 === New features in 1.32 ===
34 * (T112474) Generalized the ResourceLoader mechanism for overriding modules
35 using a particular page during edit previews.
36 * (T12331) You can now log page creation events by setting $wgPageCreationLog
37 to true.
38 * Added 'ApiParseMakeOutputPage' hook.
39 * (T174313) Added checkbox on Special:ListUsers to display only users in
40 temporary user groups.
41 * (T152462) A cookie can now be set when an IP user is blocked to track that
42 user if they move to a new IP address. This is disabled by default.
43 * (T194950) Added 'ApiMaxLagInfo' hook.
44 * SpecialPage::checkLoginSecurityLevel() will now preserve POST data when
45 reauthenticating.
46 * FormSpecialPage::execute() will now call checkLoginSecurityLevel() if
47 getLoginSecurityLevel() returns non-false.
48 * The 'ImageBeforeProduceHTML' hook is now passed three new parameters, $parser,
49 &$query and &$widthOption, allowing extensions even finer control over the
50 resulting HTML code.
51 * Added new 'ArticleShowPatrolFooter' hook, which allows extensions to determine
52 if the [mark as patrolled] link should be shown at the footer of patrollable
53 pages.
54 * The array of hidden options ($opts) passed to the 'SpecialSearchPowerBox' hook
55 is now passed by reference, allowing extensions to modify or even unset it.
56 * Added new 'OutputPageAfterGetHeadLinksArray' hook, allowing extensions to
57 modify the return value of OutputPage#getHeadLinksArray in order to add,
58 remove or otherwise alter the elements to be output in the page <head>.
59
60 === External library changes in 1.32 ===
61 * …
62
63 ==== Upgraded external libraries ====
64 * Updated QUnit from 2.4.0 to 2.6.0.
65 * Updated wikimedia/scoped-callback from 1.0.0 to 2.0.0.
66 ** ScopedCallback objects can no longer be serialized.
67 * Updated wikimedia/wrappedstring from 2.3.0 to 3.0.1.
68
69 ==== New external libraries ====
70 * Added wikimedia/xmp-reader 0.5.1
71 * …
72
73 ==== Removed and replaced external libraries ====
74 * …
75
76 === Bug fixes in 1.32 ===
77 * SpecialPage::execute() will now only call checkLoginSecurityLevel() if
78 getLoginSecurityLevel() returns non-false.
79
80 === Action API changes in 1.32 ===
81 * Added templated parameters.
82 * A module can define a templated parameter like "{fruit}-quantity", where
83 the actual parameters recognized correspond to the values of a multi-valued
84 parameter. Then clients can make requests like
85 "fruits=apples|bananas&apples-quantity=1&bananas-quantity=5".
86 * action=paraminfo will return templated parameter definitions separately
87 from normal parameters. All parameter definitions now include an "index"
88 key to allow clients to maintain parameter ordering when merging normal and
89 templated parameters.
90 * It is now an error to submit too many values for a multi-valued parameter.
91 This has generated a warning since MediaWiki 1.14.
92 * Assertion failures from the 'assert' and 'assertuser' parameters will no
93 longer use the action module's custom response format, for the few modules
94 that use custom formatters that handle errors.
95 * (T198935) User list preferences such as `email-blacklist` and similar
96 extension preferences are no longer represented as arrays when returned by
97 action=query&meta=userinfo&uiprop=options.
98
99 === Action API internal changes in 1.32 ===
100 * Added 'ApiParseMakeOutputPage' hook.
101 * Parameter names may no longer contain '{' or '}', as these are now used for
102 templated parameters.
103 * (T194950) Added 'ApiMaxLagInfo' hook.
104
105 === Languages updated in 1.32 ===
106 MediaWiki supports over 350 languages. Many localisations are updated regularly.
107 Below only new and removed languages are listed, as well as changes to languages
108 because of Phabricator reports.
109
110 * (T193566) Added language support for Ambonese Malay (abs).
111 * (T194047) Added language support for Shawiya, Latin script (shy-latn).
112 * (T195940) Added language support for Batak Mandailing (btm).
113 * (T137491) Added language support for Standard Moroccan Amazigh (zgh).
114 * (T198132) Added language support for Manipuri (mni).
115
116 === Breaking changes in 1.32 ===
117 * $wgRequestTime, deprecated in 1.25, was removed. Use
118 $_SERVER['REQUEST_TIME_FLOAT'] or WebRequest::getElapsedTime() instead.
119 * The MediaWikiI18N class, deprecated in 1.31, was removed.
120 * QuickTemplate::setTranslator(), deprecated in 1.31, was removed. Use
121 Skin::msg() instead.
122 * wfInitShellLocale(), deprecated in 1.30, was removed.
123 * wfShellExecDisabled(), deprecated in 1.30, was removed.
124 * The type string for the parameter $lang of DateFormatter::getInstance,
125 deprecated in 1.31, was removed.
126 * The EDIT_TOKEN_SUFFIX constant deprecated in 1.27, was removed. Use
127 MediaWiki\Session\Token::SUFFIX instead.
128 * EditPage::isOouiEnabled() deprecated in 1.30, was removed.
129 * mw.util.wikiGetlink(), deprecated in 1.23, was removed. Use mw.util.getUrl()
130 instead.
131 * (T61113) The following methods and constants from the Revision class, which
132 were deprecated in 1.25, have now been removed:
133 * Revision::getRawUser()
134 * Revision::getRawUserText()
135 * Revision::getRawComment()
136 * window.gM() from mediawiki.jqueryMsg, deprecated in 1.23, was removed. Use
137 mw.msg() or mw.message() instead.
138 * mw.util.escapeId(), deprecated in 1.30, was removed. Use
139 mw.util.escapeIdForAttribute or mw.util.escapeIdForLink instead.
140 * mw.util.updateTooltipAccessKeys(), deprecated in 1.24, was removed. Use
141 jquery.accessKeyLabel instead.
142 * The SqlDataUpdate class, deprecated in 1.28, has been removed.
143 * The Html5Internal and Html5Depurate tidy driver classes were removed, along
144 with the Balancer tidy implementation. Both implementations were experimental,
145 and were replaced by RemexHtml.
146 * (T179624) Job::insert() and ::batchInsert(), deprecated in 1.21, were both
147 removed. Use JobQueueGroup::singleton()->push() instead.
148 * The jquery.footHovzer module, for mediawiki.debug, was removed.
149 * The es5-shim module, empty and deprecated since 1.29, was removed.
150 * the dom-level2-shim module, empty and deprecated since 1.29, was removed.
151 * the json module, empty and deprecated since 1.29, was removed.
152 * The mediawiki.widgets.visibleByteLimit module alias, deprecated in 1.32, was
153 removed. Use mediawiki.widgets.visibleLengthLimit instead.
154 * The jquery.farbtastic module, unused since 1.18, was removed.
155 * (T181318) The $wgStyleVersion setting and its appendage to various script and
156 style URLs in OutputPage, deprecated in 1.31, was removed.
157 * The hooks 'PreferencesFormPreSave' and 'PreferencesGetLegend' may provide
158 any HTMLForm object rather than PreferencesForm.
159 * The non namespaced TimestampException class, deprecated in 1.29, was removed.
160 Use Wikimedia\Timestamp\TimestampException instead.
161 * The global functions codepointToUtf8, hexSequenceToUtf8, utf8ToHexSequence,
162 utf8ToCodepoint, and escapeSingleString (deprecated in 1.25) were removed.
163 The UtfNormal\Utils class from the utfnormal library should be used instead.
164 * The deprecated UTF8_ and UNICODE_ constants were removed. The class constants
165 from the UtfNormal\Constants class from the utfnormal library should be used
166 * (T140807) The wgResourceLoaderLESSImportPaths configuration option was removed
167 from ResourceLoader. Instead, use `@import` statements in LESS to import
168 files directly from nearby directories within the same project.
169 * The protected methods PHPSessionHandler::returnSuccess() and returnFailure(),
170 only needed for PHP5 compatibility, have been removed. It now uses the boolean
171 values `true` and `false` respectively.
172 * The $parserMemc global and wfGetParserCacheStorage(), deprecated since 1.30,
173 were removed. Use the ParserCache class instead.
174 * ScopedCallback (deprecated in 1.28) was removed. Use Wikimedia\ScopedCallback
175 instead.
176 * Support for ResourceLoaderModule::getModifiedTime() and getModifiedHash(),
177 deprecated since 1.26, was removed. Use getDefinitionSummary() instead.
178 * (T195256) Skins are recommended not to rely on JavaScript for the "mw-jump"
179 and "jump-to-nav" accessibility links. To this end, the "jquery.mw-jump"
180 is no longer loaded by default. The Vector and MonoBook skins have made a
181 minor change to implement the toggle feature with CSS instead. To restore
182 prior functionality, either explicitly load "jquery.mw-jump" in your skin
183 or refer to T195256 for details on how to make the same change.
184 * Hook 'EditPageBeforeEditChecks' was removed;
185 use 'EditPageGetCheckboxesDefinition' instead.
186 * Linker::getLinkColour() and DummyLinker::getLinkColour(), deprecated since
187 1.28, were removed. LinkRenderer::getLinkClasses() should be used instead.
188 * Wikimedia\Rdbms\LoadBalancer::getLaggedSlaveMode(), deprecated in 1.28, has
189 been removed. Use Wikimedia\Rdbms\LoadBalancer::getLaggedReplicaMode()
190 instead.
191 * mw.widgets.CategoryMultiselectWidget now uses TagMultiselectWidget instead of
192 CapsuleMultiselectWidget. The following methods may no longer be used:
193 * setItemsFromData: Use setValue instead
194 * getItemsData: Use getItems instead and get the data property
195 * LanguageCode::bcp47() now always returns a valid BCP 47 code. This means
196 that some MediaWiki-specific language codes, such as `simple`, are mapped
197 into valid BCP 47 codes (eg `en-simple`).
198
199 === Deprecations in 1.32 ===
200 * Use of a StartProfiler.php file is deprecated in favour of placing
201 configuration in LocalSettings.php.
202 * HTMLForm::setSubmitProgressive() is deprecated. No need to call it. Submit
203 button is already marked as progressive.
204 * Skin::setupSkinUserCss() is deprecated. Adding of modules to load
205 has been centralised to Skin::getDefaultModules(), which is now capable
206 of queueing style modules as well.
207 * OutputPage::addModuleScripts() and ParserOutput::addModuleScripts are
208 deprecated. Use addModules() instead.
209 * Overriding SearchEngine::{searchText,searchTitle,searchArchiveTitle}
210 in extending classes is deprecated. Extend related doSearch* methods
211 instead.
212 * CollationFa has been removed completely as it's not needed anymore
213 * The following 'mediawiki.api' plugin modules were merged into mediawiki.api
214 and deprecated: mediawiki.api.category, mediawiki.api.edit,
215 mediawiki.api.login, mediawiki.api.options, mediawiki.api.parse,
216 mediawiki.api.upload, mediawiki.api.user, mediawiki.api.watch,
217 mediawiki.api.messages, and mediawiki.api.rollback.
218 * ApiBase::truncateArray() is deprecated. No replacement, as nothing is known
219 to use it.
220 * WatchAction::getUnwatchToken is deprecated. Use WatchAction::getWatchToken
221 with the 'unwatch' action parameter instead.
222 * IcuCollation::getICUVersion() is deprecated, as you can just use the PHP
223 constant INTL_ICU_VERSION directly in all versions that MediaWiki supports.
224 * Parser::fetchFile() is deprecated. Use ::fetchFileAndTitle() instead.
225 * The ApiQueryContributions class has been renamed to ApiQueryUserContribs.
226 * The XMPInfo, XMPReader, and XMPValidate classes have been deprecated in favor
227 of the namespaced classes provided by the wikimedia/xmp-reader library.
228 * SearchResultSet::{next,rewind} are deprecated. Calling code should
229 use foreach on the SearchResultSet, or the extractResults method. Extending
230 code should override extractResults.
231 * Instantiating SearchResultSet directly is deprecated. SearchEngine
232 implementations must subclass SearchResultSet for their purposes.
233 * SearchResult::setExtensionData argument has been changed from accepting an
234 array to accepting a Closure that returns the array when called.
235 * Class CryptRand, everything in MWCryptRand except generateHex() and function
236 MediaWikiServices::getCryptRand() are deprecated, use random_bytes() to
237 generate cryptographically secure random byte sequences.
238 * Parser::getConverterLanguage() is deprecated. Use ::getTargetLanguage()
239 instead.
240 * Language::markNoConversion() is deprecated. It confused readers because
241 it had unexpected behavior (only marking text if it looked like a URL)
242 and was only used in a single place in the code. Use
243 LanguageConverter::markNoConversion() instead.
244 * (T197492) Language::truncate() was soft deprecated in 1.31 and is
245 hard deprecated in this release. It has been split into two similar
246 methods, Language::truncateForVisual() and Language::truncateForDatabase(),
247 which measure length in characters and bytes, respectively. Use
248 Language::truncateForVisual() when possible to provide equity to users
249 of multibyte scripts.
250 * (T176526) EditPage::getContextTitle() falling back to $wgTitle when the
251 context title is unset is now deprecated; anything creating an EditPage
252 instance should set the context title via ::setContextTitle().
253 * The 'jquery.hidpi' module (polyfill for IMG srcset) is deprecated.
254 * ResourceLoaderStartUpModule::getStartupModules() and ::getLegacyModules()
255 are deprecated. These concepts are obsolete and have no replacement.
256 * String type for $lang of DifferenceEngine::setTextLanguage is deprecated.
257 * The following methods of OutputPage are now deprecated in favour
258 of using showFatalError directly: OutputPage::showFileDeleteError()
259 OutputPage::showFileNotFoundError(), OutputPage::showFileRenameError()
260 OutputPage::showFileCopyError() and OutputPage::showUnexpectedValueError().
261 * The Replacer, DoubleReplacer, HashtableReplacer, and RegexlikeReplacer
262 classes are now deprecated. Use a Closure instead.
263 * (T194263) ContentHandler::makeParserOptions() is deprecated. Use
264 WikiPage::makeParserOptions() or ParserOptions::newCanonical() instead.
265 * (T100681) Use of the Parsoid v1 API with the VirtualRESTService, deprecated in
266 MediaWiki 1.26, is now hard-deprecated. All known clients were converted to
267 the Parsoid v3 API in May 2015.
268 * $input is deprecated in hook 'LogEventsListGetExtraInputs'. Use
269 $formDescriptor instead.
270 * SearchEngine::transformSearchTerm( $term ) should no longer be called prior
271 to running searchText. This method was mainly implemented to support the
272 'prefix' URI param in SpecialSearch, but there are no reasons to expose this
273 logic as it should be handled internally by SearchEngine implementations
274 supporting this feature. SearchEngine implementations should no longer
275 override this methods.
276 * SearchEngine::replacePrefixes( $query ) should no longer be called prior
277 to running searchText/searchTitle.
278 * (T199657) Messages for $wgFilterLogTypes labels should be no longer be in the
279 'log-show-hide-[type]' format. Instead use 'logeventslist-[type]-log'.
280 * Global functions wfArrayFilter() and wfArrayFilterByKey() are deprecated.
281 use array_filter() directly.
282
283 === Other changes in 1.32 ===
284 * (T198811) The following tables have had their UNIQUE indexes turned into
285 proper PRIMARY KEYs for increased maintainability: interwiki, page_props,
286 protected_titles and site_identifiers.
287 * …
288
289 == Compatibility ==
290 MediaWiki 1.32 requires PHP 7.0.0 or later. Although HHVM 3.18.5 or later is
291 supported, it is generally advised to use PHP 7.0.0 or later for long term
292 support.
293
294 MySQL/MariaDB is the recommended DBMS. PostgreSQL or SQLite can also be used,
295 but support for them is somewhat less mature. There is experimental support for
296 Oracle and Microsoft SQL Server.
297
298 The supported versions are:
299
300 * MySQL 5.5.8 or later
301 * PostgreSQL 9.2 or later
302 * SQLite 3.3.7 or later
303 * Oracle 9.0.1 or later
304 * Microsoft SQL Server 2005 (9.00.1399)
305
306 == Upgrading ==
307 1.32 has several database changes since 1.31, and will not work without schema
308 updates. Note that due to changes to some very large tables like the revision
309 table, the schema update may take quite long (minutes on a medium sized site,
310 many hours on a large site).
311
312 Don't forget to always back up your database before upgrading!
313
314 See the file UPGRADE for more detailed upgrade instructions, including
315 important information when upgrading from versions prior to 1.11.
316
317 For notes on 1.31.x and older releases, see HISTORY.
318
319 == Online documentation ==
320 Documentation for both end-users and site administrators is available on
321 MediaWiki.org, and is covered under the GNU Free Documentation License (except
322 for pages that explicitly state that their contents are in the public domain):
323
324 https://www.mediawiki.org/wiki/Special:MyLanguage/Documentation
325
326 == Mailing list ==
327 A mailing list is available for MediaWiki user support and discussion:
328
329 https://lists.wikimedia.org/mailman/listinfo/mediawiki-l
330
331 A low-traffic announcements-only list is also available:
332
333 https://lists.wikimedia.org/mailman/listinfo/mediawiki-announce
334
335 It's highly recommended that you sign up for one of these lists if you're
336 going to run a public MediaWiki, so you can be notified of security fixes.
337
338 == IRC help ==
339 There's usually someone online in #mediawiki on irc.freenode.net.