Add PasswordFactory to MediaWikiServices
[lhc/web/wiklou.git] / RELEASE-NOTES-1.32
1 == MediaWiki 1.32 ==
2
3 THIS IS NOT A RELEASE YET
4
5 MediaWiki 1.32 is an alpha-quality branch and is not recommended for use in
6 production.
7
8 === Configuration changes in 1.32 ===
9 * (T115414) The $wgEnableAPI and $wgEnableWriteAPI settings, deprecated in 1.31,
10 have been removed.
11 * The $wgUseAjax setting, deprecated in 1.31, is now ignored.
12 * The $wgSiteSupportPage setting, unused since 1.5, was removed.
13 * The $wgBrowserBlacklist setting, deprecated in 1.30, was removed.
14 * The default quality of JPEG thumbnails generated by GD was reduced from 95 to
15 80. The quality of JPEG thumbnails is now configurable through the new setting
16 $wgJpegQuality (default 80). This aligns the quality to what ImageMagick uses.
17 * $wgExperimentalHtmlIds, deprecated since 1.30, has been removed. The
18 'html5-legacy' value for $wgFragmentMode is no longer accepted.
19 * The experimental Html5Internal and Html5Depurate tidy drivers were removed.
20 RemexHtml, which is the default, should be used instead.
21 * (T135963) You can now define a Content Security Policy for your wiki. This
22 adds a defense-in-depth feature to stop an attacker who has found a bug in
23 the parser allowing them to insert malicious attributes. Disabled by default,
24 you can configure this via $wgCSPHeader and $wgCSPReportOnlyHeader.
25 * New configuration variable has been added: $wgCookieSetOnIpBlock.
26 This determines whether to set a cookie when an IP user is blocked. Doing so
27 means that a blocked user, even after moving to a new IP address, will still
28 be blocked.
29 * The archive table's ar_rev_id field is now unique.
30 * Special:BotPasswords now requires reauthentication.
31 * (T194414) The default watchlist view time has been increased from 3 to 7 days.
32 * The right to edit sitewide Javascript (e.g. MediaWiki:Common.js), CSS or JSON
33 was separated from 'editinterface' and is available under
34 'editsitejs'/'editsitecss'/'editsitejson'. Having 'editinterface' is still
35 necessary to edit such pages.
36 * A new user group, 'interface-admin', is added for controlling access to
37 sitewide CSS/JS (and editing other users' CSS/JS). No other group has
38 'editsitecss', 'editusercss', 'editsitejs' or 'edituserjs' by default.
39 * A new grant group, 'editsiteconfig', is added for granting the above rights.
40
41 === New features in 1.32 ===
42 * (T112474) Generalized the ResourceLoader mechanism for overriding modules
43 using a particular page during edit previews.
44 * (T12331) You can now log page creation events by setting $wgPageCreationLog
45 to true.
46 * Added 'ApiParseMakeOutputPage' hook.
47 * (T174313) Added checkbox on Special:ListUsers to display only users in
48 temporary user groups.
49 * (T152462) A cookie can now be set when an IP user is blocked to track that
50 user if they move to a new IP address. This is disabled by default.
51 * (T194950) Added 'ApiMaxLagInfo' hook.
52 * SpecialPage::checkLoginSecurityLevel() will now preserve POST data when
53 reauthenticating.
54 * FormSpecialPage::execute() will now call checkLoginSecurityLevel() if
55 getLoginSecurityLevel() returns non-false.
56 * The 'ImageBeforeProduceHTML' hook is now passed three new parameters, $parser,
57 &$query and &$widthOption, allowing extensions even finer control over the
58 resulting HTML code.
59 * Added new 'ArticleShowPatrolFooter' hook, which allows extensions to determine
60 if the [mark as patrolled] link should be shown at the footer of patrollable
61 pages.
62 * The array of hidden options ($opts) passed to the 'SpecialSearchPowerBox' hook
63 is now passed by reference, allowing extensions to modify or even unset it.
64 * Added new 'OutputPageAfterGetHeadLinksArray' hook, allowing extensions to
65 modify the return value of OutputPage#getHeadLinksArray in order to add,
66 remove or otherwise alter the elements to be output in the page <head>.
67 * (T28934) The 'HistoryPageToolLinks' hook allows extensions to append
68 additional links to the subtitle of a history page.
69 * The 'GetLinkColours' hook now receives an additional $title parameter,
70 the Title object of the page being parsed, on which the links will be shown.
71
72 === External library changes in 1.32 ===
73 * …
74
75 ==== Upgraded external libraries ====
76 * Updated QUnit from 2.4.0 to 2.6.0.
77 * Updated wikimedia/scoped-callback from 1.0.0 to 2.0.0.
78 ** ScopedCallback objects can no longer be serialized.
79 * Updated wikimedia/wrappedstring from 2.3.0 to 3.0.1.
80 * Updated mediawiki/mediawiki-codesniffer from v20.0.0 to v21.0.0.
81 * Updated composer/spdx-licenses from 1.3.0 to 1.4.0.
82 * Updated jquery.i18n from 1.0.4 to 1.0.5.
83
84 ==== New external libraries ====
85 * Added wikimedia/xmp-reader 0.5.1
86 * …
87
88 ==== Removed and replaced external libraries ====
89 * …
90
91 === Bug fixes in 1.32 ===
92 * SpecialPage::execute() will now only call checkLoginSecurityLevel() if
93 getLoginSecurityLevel() returns non-false.
94
95 === Action API changes in 1.32 ===
96 * Added templated parameters.
97 * A module can define a templated parameter like "{fruit}-quantity", where
98 the actual parameters recognized correspond to the values of a multi-valued
99 parameter. Then clients can make requests like
100 "fruits=apples|bananas&apples-quantity=1&bananas-quantity=5".
101 * action=paraminfo will return templated parameter definitions separately
102 from normal parameters. All parameter definitions now include an "index"
103 key to allow clients to maintain parameter ordering when merging normal and
104 templated parameters.
105 * It is now an error to submit too many values for a multi-valued parameter.
106 This has generated a warning since MediaWiki 1.14.
107 * Assertion failures from the 'assert' and 'assertuser' parameters will no
108 longer use the action module's custom response format, for the few modules
109 that use custom formatters that handle errors.
110 * (T198935) User list preferences such as `email-blacklist` and similar
111 extension preferences are no longer represented as arrays when returned by
112 action=query&meta=userinfo&uiprop=options.
113 * 'missingparam' errors will now use the prefixed parameter name in the code
114 and error text, e.g. "noxxfoo" and "The 'xxfoo' parameter must be set" rather
115 than "nofoo" and "The 'foo' parameter must be set".
116 * action=query&prop=revisions now takes a 'rvslots' parameter to indicate the
117 multi-content revision slots for which content should be returned. It also
118 has a new rvprop, 'roles', to indicate which roles have slots. A deprecation
119 warning will be issued if rvprop=content or rvprop=contentmodel are used
120 without rvslots.
121 * The rvcontentformat parameter to action=query&prop=revisions has been
122 deprecated. Clients should be prepared to deal with the default format for
123 relevant models.
124 * Use of the deprecated parameters rvexpandtemplates, rvgeneratexml, rvparse,
125 rvdiffto, rvdifftotext, rvdifftotextpst, rvcontentformat, or the deprecated
126 rvprop=parsetree is forbidden with the new 'rvslots' parameter.
127 * action=query&prop=deletedrevisions, action=query&list=allrevisions, and
128 action=query&list=alldeletedrevisions are changed similarly to
129 &prop=revisions (see the three previous items).
130
131 === Action API internal changes in 1.32 ===
132 * Added 'ApiParseMakeOutputPage' hook.
133 * Parameter names may no longer contain '{' or '}', as these are now used for
134 templated parameters.
135 * (T194950) Added 'ApiMaxLagInfo' hook.
136 * Added 'ApiParseMakeOutputPage' hook.
137 * The following methods now take a RevisionRecord rather than a Revision. No
138 external callers are known.
139 * ApiFeedContributions::feedItemAuthor()
140 * ApiFeedContributions::feedItemDesc()
141 * ApiQueryRevisionsBase::extractRevisionInfo()
142
143 === Languages updated in 1.32 ===
144 MediaWiki supports over 350 languages. Many localisations are updated regularly.
145 Below only new and removed languages are listed, as well as changes to languages
146 because of Phabricator reports.
147
148 * (T193566) Added language support for Ambonese Malay (abs).
149 * (T194047) Added language support for Shawiya, Latin script (shy-latn).
150 * (T195940) Added language support for Batak Mandailing (btm).
151 * (T137491) Added language support for Standard Moroccan Amazigh (zgh).
152 * (T198132) Added language support for Manipuri (mni).
153
154 === Breaking changes in 1.32 ===
155 * $wgRequestTime, deprecated in 1.25, was removed. Use
156 $_SERVER['REQUEST_TIME_FLOAT'] or WebRequest::getElapsedTime() instead.
157 * The MediaWikiI18N class, deprecated in 1.31, was removed.
158 * QuickTemplate::setTranslator(), deprecated in 1.31, was removed. Use
159 Skin::msg() instead.
160 * wfInitShellLocale(), deprecated in 1.30, was removed.
161 * wfShellExecDisabled(), deprecated in 1.30, was removed.
162 * The type string for the parameter $lang of DateFormatter::getInstance,
163 deprecated in 1.31, was removed.
164 * The EDIT_TOKEN_SUFFIX constant deprecated in 1.27, was removed. Use
165 MediaWiki\Session\Token::SUFFIX instead.
166 * EditPage::isOouiEnabled() deprecated in 1.30, was removed.
167 * mw.util.wikiGetlink(), deprecated in 1.23, was removed. Use mw.util.getUrl()
168 instead.
169 * (T61113) The following methods and constants from the Revision class, which
170 were deprecated in 1.25, have now been removed:
171 * Revision::getRawUser()
172 * Revision::getRawUserText()
173 * Revision::getRawComment()
174 * window.gM() from mediawiki.jqueryMsg, deprecated in 1.23, was removed. Use
175 mw.msg() or mw.message() instead.
176 * mw.util.escapeId(), deprecated in 1.30, was removed. Use
177 mw.util.escapeIdForAttribute or mw.util.escapeIdForLink instead.
178 * mw.util.updateTooltipAccessKeys(), deprecated in 1.24, was removed. Use
179 jquery.accessKeyLabel instead.
180 * The SqlDataUpdate class, deprecated in 1.28, has been removed.
181 * The Html5Internal and Html5Depurate tidy driver classes were removed, along
182 with the Balancer tidy implementation. Both implementations were experimental,
183 and were replaced by RemexHtml.
184 * (T179624) Job::insert() and ::batchInsert(), deprecated in 1.21, were both
185 removed. Use JobQueueGroup::singleton()->push() instead.
186 * The jquery.footHovzer module, for mediawiki.debug, was removed.
187 * The es5-shim module, empty and deprecated since 1.29, was removed.
188 * the dom-level2-shim module, empty and deprecated since 1.29, was removed.
189 * the json module, empty and deprecated since 1.29, was removed.
190 * The mediawiki.widgets.visibleByteLimit module alias, deprecated in 1.32, was
191 removed. Use mediawiki.widgets.visibleLengthLimit instead.
192 * The jquery.farbtastic module, unused since 1.18, was removed.
193 * (T181318) The $wgStyleVersion setting and its appendage to various script and
194 style URLs in OutputPage, deprecated in 1.31, was removed.
195 * The hooks 'PreferencesFormPreSave' and 'PreferencesGetLegend' may provide
196 any HTMLForm object rather than PreferencesForm.
197 * The non namespaced TimestampException class, deprecated in 1.29, was removed.
198 Use Wikimedia\Timestamp\TimestampException instead.
199 * The global functions codepointToUtf8, hexSequenceToUtf8, utf8ToHexSequence,
200 utf8ToCodepoint, and escapeSingleString (deprecated in 1.25) were removed.
201 The UtfNormal\Utils class from the utfnormal library should be used instead.
202 * The deprecated UTF8_ and UNICODE_ constants were removed. The class constants
203 from the UtfNormal\Constants class from the utfnormal library should be used
204 * (T140807) The wgResourceLoaderLESSImportPaths configuration option was removed
205 from ResourceLoader. Instead, use `@import` statements in LESS to import
206 files directly from nearby directories within the same project.
207 * The protected methods PHPSessionHandler::returnSuccess() and returnFailure(),
208 only needed for PHP5 compatibility, have been removed. It now uses the boolean
209 values `true` and `false` respectively.
210 * The $parserMemc global and wfGetParserCacheStorage(), deprecated since 1.30,
211 were removed. Use the ParserCache class instead.
212 * ScopedCallback (deprecated in 1.28) was removed. Use Wikimedia\ScopedCallback
213 instead.
214 * Support for ResourceLoaderModule::getModifiedTime() and getModifiedHash(),
215 deprecated since 1.26, was removed. Use getDefinitionSummary() instead.
216 * (T195256) Skins are recommended not to rely on JavaScript for the "mw-jump"
217 and "jump-to-nav" accessibility links. To this end, the "jquery.mw-jump"
218 is no longer loaded by default. The Vector and MonoBook skins have made a
219 minor change to implement the toggle feature with CSS instead. To restore
220 prior functionality, either explicitly load "jquery.mw-jump" in your skin
221 or refer to T195256 for details on how to make the same change.
222 * Hook 'EditPageBeforeEditChecks' was removed;
223 use 'EditPageGetCheckboxesDefinition' instead.
224 * Linker::getLinkColour() and DummyLinker::getLinkColour(), deprecated since
225 1.28, were removed. LinkRenderer::getLinkClasses() should be used instead.
226 * Wikimedia\Rdbms\LoadBalancer::getLaggedSlaveMode(), deprecated in 1.28, has
227 been removed. Use Wikimedia\Rdbms\LoadBalancer::getLaggedReplicaMode()
228 instead.
229 * mw.widgets.CategoryMultiselectWidget now uses TagMultiselectWidget instead of
230 CapsuleMultiselectWidget. The following methods may no longer be used:
231 * setItemsFromData: Use setValue instead
232 * getItemsData: Use getItems instead and get the data property
233 * Two OutputPage methods, addMetadataLink() and getMetadataAttribute(), were
234 removed. Use addLink() instead.
235 * Another two OutputPage methods, setPageTitleActionText() and
236 getPageTitleActionText(), were removed. They did nothing since 1.15 (almost
237 ten years). Use setHTMLTitle() directly.
238 * All MagicWord static member variables have been removed. Use appropriate
239 hooks or MagicWordFactory methods instead.
240 * MagicWord::clearCache() has been removed. Instead, create a new
241 MagicWordFactory, such as by calling
242 resetServiceForTesting( 'MagicWordFactory' ) on a MediaWikiServices.
243
244 === Deprecations in 1.32 ===
245 * Use of a StartProfiler.php file is deprecated in favour of placing
246 configuration in LocalSettings.php.
247 * HTMLForm::setSubmitProgressive() is deprecated. No need to call it. Submit
248 button is already marked as progressive.
249 * Skin::setupSkinUserCss() is deprecated. Adding of modules to load
250 has been centralised to Skin::getDefaultModules(), which is now capable
251 of queueing style modules as well.
252 * OutputPage::addModuleScripts() and ParserOutput::addModuleScripts are
253 deprecated. Use addModules() instead.
254 * Overriding SearchEngine::{searchText,searchTitle,searchArchiveTitle}
255 in extending classes is deprecated. Extend related doSearch* methods
256 instead.
257 * CollationFa has been removed completely as it's not needed anymore
258 * The following 'mediawiki.api' plugin modules were merged into mediawiki.api
259 and deprecated: mediawiki.api.category, mediawiki.api.edit,
260 mediawiki.api.login, mediawiki.api.options, mediawiki.api.parse,
261 mediawiki.api.upload, mediawiki.api.user, mediawiki.api.watch,
262 mediawiki.api.messages, and mediawiki.api.rollback.
263 * ApiBase::truncateArray() is deprecated. No replacement, as nothing is known
264 to use it.
265 * WatchAction::getUnwatchToken is deprecated. Use WatchAction::getWatchToken
266 with the 'unwatch' action parameter instead.
267 * IcuCollation::getICUVersion() is deprecated, as you can just use the PHP
268 constant INTL_ICU_VERSION directly in all versions that MediaWiki supports.
269 * Parser::fetchFile() is deprecated. Use ::fetchFileAndTitle() instead.
270 * The ApiQueryContributions class has been renamed to ApiQueryUserContribs.
271 * The XMPInfo, XMPReader, and XMPValidate classes have been deprecated in favor
272 of the namespaced classes provided by the wikimedia/xmp-reader library.
273 * SearchResultSet::{next,rewind} are deprecated. Calling code should
274 use foreach on the SearchResultSet, or the extractResults method. Extending
275 code should override extractResults.
276 * Instantiating SearchResultSet directly is deprecated. SearchEngine
277 implementations must subclass SearchResultSet for their purposes.
278 * SearchResult::setExtensionData argument has been changed from accepting an
279 array to accepting a Closure that returns the array when called.
280 * Class CryptRand, everything in MWCryptRand except generateHex() and function
281 MediaWikiServices::getCryptRand() are deprecated, use random_bytes() to
282 generate cryptographically secure random byte sequences.
283 * Parser::getConverterLanguage() is deprecated. Use ::getTargetLanguage()
284 instead.
285 * Language::markNoConversion() is deprecated. It confused readers because
286 it had unexpected behavior (only marking text if it looked like a URL)
287 and was only used in a single place in the code. Use
288 LanguageConverter::markNoConversion() instead.
289 * (T197492) Language::truncate() was soft deprecated in 1.31 and is
290 hard deprecated in this release. It has been split into two similar
291 methods, Language::truncateForVisual() and Language::truncateForDatabase(),
292 which measure length in characters and bytes, respectively. Use
293 Language::truncateForVisual() when possible to provide equity to users
294 of multibyte scripts.
295 * (T176526) EditPage::getContextTitle() falling back to $wgTitle when the
296 context title is unset is now deprecated; anything creating an EditPage
297 instance should set the context title via ::setContextTitle().
298 * The 'jquery.hidpi' module (polyfill for IMG srcset) is deprecated.
299 * ResourceLoaderStartUpModule::getStartupModules() and ::getLegacyModules()
300 are deprecated. These concepts are obsolete and have no replacement.
301 * String type for $lang of DifferenceEngine::setTextLanguage is deprecated.
302 * The following methods of OutputPage are now deprecated in favour
303 of using showFatalError directly: OutputPage::showFileDeleteError()
304 OutputPage::showFileNotFoundError(), OutputPage::showFileRenameError()
305 OutputPage::showFileCopyError() and OutputPage::showUnexpectedValueError().
306 * The Replacer, DoubleReplacer, HashtableReplacer, and RegexlikeReplacer
307 classes are now deprecated. Use a Closure instead.
308 * (T194263) ContentHandler::makeParserOptions() is deprecated. Use
309 WikiPage::makeParserOptions() or ParserOptions::newCanonical() instead.
310 * (T100681) Use of the Parsoid v1 API with the VirtualRESTService, deprecated in
311 MediaWiki 1.26, is now hard-deprecated. All known clients were converted to
312 the Parsoid v3 API in May 2015.
313 * $input is deprecated in hook 'LogEventsListGetExtraInputs'. Use
314 $formDescriptor instead.
315 * SearchEngine::transformSearchTerm( $term ) should no longer be called prior
316 to running searchText. This method was mainly implemented to support the
317 'prefix' URI param in SpecialSearch, but there are no reasons to expose this
318 logic as it should be handled internally by SearchEngine implementations
319 supporting this feature. SearchEngine implementations should no longer
320 override this methods.
321 * SearchEngine::replacePrefixes( $query ) should no longer be called prior
322 to running searchText/searchTitle.
323 * (T199657) Messages for $wgFilterLogTypes labels should be no longer be in the
324 'log-show-hide-[type]' format. Instead use 'logeventslist-[type]-log'.
325 * Global functions wfArrayFilter() and wfArrayFilterByKey() are deprecated.
326 use array_filter() directly.
327 * The $wgShowSQLErrors global is deprecated and nonfunctional.
328 Set $wgShowExceptionDetails and/or $wgShowHostnames instead.
329 * The $wgShowDBErrorBacktrace global is deprecated and nonfunctional.
330 Set $wgShowExceptionDetails instead.
331 * Public access to the DifferenceEngine properties mOldid, mNewid, mOldPage,
332 mNewPage, mOldContent, mNewContent, mRevisionsLoaded, mTextLoaded and
333 mCacheHit is deprecated. Use getOldid() / getNewid() for the first two,
334 do your own lookup for page/content. mNewRev / mOldRev remains public.
335 * The $wgExternalDiffEngine value 'wikidiff2' is deprecated. To use wikidiff2
336 just enable the PHP extension, and it will be autodetected.
337 * The wfUseMW function, soft-deprecated in 1.26, is now hard deprecated.
338 * All MagicWord static methods are now deprecated. Use the MagicWordFactory
339 methods instead.
340 * PasswordFactory::init is deprecated. To get a password factory with the
341 standard configuration, use MediaWikiServices::getPasswordFactory.
342
343 === Other changes in 1.32 ===
344 * (T198811) The following tables have had their UNIQUE indexes turned into
345 proper PRIMARY KEYs for increased maintainability: interwiki, page_props,
346 protected_titles and site_identifiers.
347 * …
348
349 == Compatibility ==
350 MediaWiki 1.32 requires PHP 7.0.0 or later. Although HHVM 3.18.5 or later is
351 supported, it is generally advised to use PHP 7.0.0 or later for long term
352 support.
353
354 MySQL/MariaDB is the recommended DBMS. PostgreSQL or SQLite can also be used,
355 but support for them is somewhat less mature. There is experimental support for
356 Oracle and Microsoft SQL Server.
357
358 The supported versions are:
359
360 * MySQL 5.5.8 or later
361 * PostgreSQL 9.2 or later
362 * SQLite 3.3.7 or later
363 * Oracle 9.0.1 or later
364 * Microsoft SQL Server 2005 (9.00.1399)
365
366 == Upgrading ==
367 1.32 has several database changes since 1.31, and will not work without schema
368 updates. Note that due to changes to some very large tables like the revision
369 table, the schema update may take quite long (minutes on a medium sized site,
370 many hours on a large site).
371
372 Don't forget to always back up your database before upgrading!
373
374 See the file UPGRADE for more detailed upgrade instructions, including
375 important information when upgrading from versions prior to 1.11.
376
377 For notes on 1.31.x and older releases, see HISTORY.
378
379 == Online documentation ==
380 Documentation for both end-users and site administrators is available on
381 MediaWiki.org, and is covered under the GNU Free Documentation License (except
382 for pages that explicitly state that their contents are in the public domain):
383
384 https://www.mediawiki.org/wiki/Special:MyLanguage/Documentation
385
386 == Mailing list ==
387 A mailing list is available for MediaWiki user support and discussion:
388
389 https://lists.wikimedia.org/mailman/listinfo/mediawiki-l
390
391 A low-traffic announcements-only list is also available:
392
393 https://lists.wikimedia.org/mailman/listinfo/mediawiki-announce
394
395 It's highly recommended that you sign up for one of these lists if you're
396 going to run a public MediaWiki, so you can be notified of security fixes.
397
398 == IRC help ==
399 There's usually someone online in #mediawiki on irc.freenode.net.