parser: Validate $length in padleft/padright parser functions
[lhc/web/wiklou.git] / RELEASE-NOTES-1.32
1 == MediaWiki 1.32 ==
2
3 THIS IS NOT A RELEASE YET
4
5 MediaWiki 1.32 is an alpha-quality branch and is not recommended for use in
6 production.
7
8 === Configuration changes in 1.32 ===
9 * (T115414) The $wgEnableAPI and $wgEnableWriteAPI settings, deprecated in 1.31,
10 have been removed.
11 * The $wgUseAjax setting, deprecated in 1.31, is now ignored.
12 * The $wgSiteSupportPage setting, unused since 1.5, was removed.
13 * The default quality of JPEG thumbnails generated by GD was reduced from 95 to
14 80. The quality of JPEG thumbnails is now configurable through the new setting
15 $wgJpegQuality (default 80). This aligns the quality to what ImageMagick uses.
16 * $wgExperimentalHtmlIds, deprecated since 1.30, has been removed. The
17 'html5-legacy' value for $wgFragmentMode is no longer accepted.
18 * The experimental Html5Internal and Html5Depurate tidy drivers were removed.
19 RemexHtml, which is the default, should be used instead.
20 * (T135963) You can now define a Content Security Policy for your wiki. This
21 adds a defense-in-depth feature to stop an attacker who has found a bug in
22 the parser allowing them to insert malicious attributes. Disabled by default,
23 you can configure this via $wgCSPHeader and $wgCSPReportOnlyHeader.
24 * New configuration variable has been added: $wgCookieSetOnIpBlock.
25 This determines whether to set a cookie when an IP user is blocked. Doing so means
26 that a blocked user, even after moving to a new IP address, will still be blocked.
27 * The archive table's ar_rev_id field is now unique.
28
29 === New features in 1.32 ===
30 * (T112474) Generalized the ResourceLoader mechanism for overriding modules
31 using a particular page during edit previews.
32 * (T12331) You can now log page creation events by setting $wgPageCreationLog
33 to true.
34 * Added 'ApiParseMakeOutputPage' hook.
35 * (T174313) Added checkbox on Special:ListUsers to display only users in
36 temporary user groups.
37 * (T152462) A cookie can now be set when an IP user is blocked to track that user if
38 they move to a new IP address. This is disabled by default.
39 * (T194950) Added 'ApiMaxLagInfo' hook.
40 * SpecialPage::checkLoginSecurityLevel() will now preserve POST data when
41 reauthenticating.
42 * FormSpecialPage::execute() will now call checkLoginSecurityLevel() if
43 getLoginSecurityLevel() returns non-false.
44
45 === External library changes in 1.32 ===
46 * …
47
48 ==== Upgraded external libraries ====
49 * Updated QUnit from 2.4.0 to 2.6.0.
50 * Updated wikimedia/scoped-callback from 1.0.0 to 2.0.0.
51 ** ScopedCallback objects can no longer be serialized.
52 * Updated wikimedia/wrappedstring from 2.3.0 to 3.0.1.
53
54 ==== New external libraries ====
55 * Added wikimedia/xmp-reader 0.5.1
56 * …
57
58 ==== Removed and replaced external libraries ====
59 * …
60
61 === Bug fixes in 1.32 ===
62 * SpecialPage::execute() will now only call checkLoginSecurityLevel() if
63 getLoginSecurityLevel() returns non-false.
64
65 === Action API changes in 1.32 ===
66 * Added templated parameters.
67 * A module can define a templated parameter like "{fruit}-quantity", where
68 the actual parameters recognized correspond to the values of a multi-valued
69 parameter. Then clients can make requests like
70 "fruits=apples|bananas&apples-quantity=1&bananas-quantity=5".
71 * action=paraminfo will return templated parameter definitions separately
72 from normal parameters. All parameter definitions now include an "index"
73 key to allow clients to maintain parameter ordering when merging normal and
74 templated parameters.
75 * It is now an error to submit too many values for a multi-valued parameter.
76 This has generated a warning since MediaWiki 1.14.
77
78 === Action API internal changes in 1.32 ===
79 * Added 'ApiParseMakeOutputPage' hook.
80 * Parameter names may no longer contain '{' or '}', as these are now used for
81 templated parameters.
82 * (T194950) Added 'ApiMaxLagInfo' hook.
83
84 === Languages updated in 1.32 ===
85 MediaWiki supports over 350 languages. Many localisations are updated regularly.
86 Below only new and removed languages are listed, as well as changes to languages
87 because of Phabricator reports.
88
89 * (T193566) Added language support for Ambonese Malay (abs).
90 * (T194047) Added language support for Shawiya, Latin script (shy-latn).
91 * (T195940) Added language support for Batak Mandailing (btm).
92
93 === Breaking changes in 1.32 ===
94 * $wgRequestTime, deprecated in 1.25, was removed. Use
95 $_SERVER['REQUEST_TIME_FLOAT'] or WebRequest::getElapsedTime() instead.
96 * The MediaWikiI18N class, deprecated in 1.31, was removed.
97 * QuickTemplate::setTranslator(), deprecated in 1.31, was removed. Use
98 Skin::msg() instead.
99 * wfInitShellLocale(), deprecated in 1.30, was removed.
100 * wfShellExecDisabled(), deprecated in 1.30, was removed.
101 * The type string for the parameter $lang of DateFormatter::getInstance,
102 deprecated in 1.31, was removed.
103 * The EDIT_TOKEN_SUFFIX constant deprecated in 1.27, was removed. Use
104 MediaWiki\Session\Token::SUFFIX instead.
105 * EditPage::isOouiEnabled() deprecated in 1.30, was removed.
106 * mw.util.wikiGetlink(), deprecated in 1.23, was removed. Use mw.util.getUrl()
107 instead.
108 * (T61113) The following methods and constants from the Revision class, which
109 were deprecated in 1.25, have now been removed:
110 * Revision::getRawUser()
111 * Revision::getRawUserText()
112 * Revision::getRawComment()
113 * window.gM() from mediawiki.jqueryMsg, deprecated in 1.23, was removed. Use
114 mw.msg() or mw.message() instead.
115 * mw.util.escapeId(), deprecated in 1.30, was removed. Use
116 mw.util.escapeIdForAttribute or mw.util.escapeIdForLink instead.
117 * mw.util.updateTooltipAccessKeys(), deprecated in 1.24, was removed. Use
118 jquery.accessKeyLabel instead.
119 * The SqlDataUpdate class, deprecated in 1.28, has been removed.
120 * The Html5Internal and Html5Depurate tidy driver classes were removed, along
121 with the Balancer tidy implementation. Both implementations were experimental,
122 and were replaced by RemexHtml.
123 * (T179624) Job::insert() and ::batchInsert(), deprecated in 1.21, were both
124 removed. Use JobQueueGroup::singleton()->push() instead.
125 * The jquery.footHovzer module, for mediawiki.debug, was removed.
126 * The es5-shim module, empty and deprecated since 1.29, was removed.
127 * The mediawiki.widgets.visibleByteLimit module alias, deprecated in 1.32, was
128 removed. Use mediawiki.widgets.visibleLengthLimit instead.
129 * The jquery.farbtastic module, unused since 1.18, was removed.
130 * (T181318) The $wgStyleVersion setting and its appendage to various script and
131 style URLs in OutputPage, deprecated in 1.31, was removed.
132 * The hooks 'PreferencesFormPreSave' and 'PreferencesGetLegend' may provide
133 any HTMLForm object rather than PreferencesForm.
134 * The non namespaced TimestampException class, deprecated in 1.29, was removed.
135 Use Wikimedia\Timestamp\TimestampException instead.
136 * The global functions codepointToUtf8, hexSequenceToUtf8, utf8ToHexSequence,
137 utf8ToCodepoint, and escapeSingleString (deprecated in 1.25) were removed.
138 The UtfNormal\Utils class from the utfnormal library should be used instead.
139 * The deprecated UTF8_ and UNICODE_ constants were removed. The class constants
140 from the UtfNormal\Constants class from the utfnormal library should be used
141 * (T140807) The wgResourceLoaderLESSImportPaths configuration option was removed
142 from ResourceLoader. Instead, use `@import` statements in LESS to import
143 files directly from nearby directories within the same project.
144 * The protected methods PHPSessionHandler::returnSuccess() and returnFailure(),
145 only needed for PHP5 compatibility, have been removed. It now uses the boolean
146 values `true` and `false` respectively.
147 * The $parserMemc global and wfGetParserCacheStorage(), deprecated since 1.30,
148 were removed. Use the ParserCache class instead.
149 * ScopedCallback (deprecated in 1.28) was removed. Use Wikimedia\ScopedCallback
150 instead.
151 * Support for ResourceLoaderModule::getModifiedTime() and getModifiedHash(),
152 deprecated since 1.26, was removed. Use getDefinitionSummary() instead.
153 * (T195256) Skins are recommended not to rely on JavaScript for the "mw-jump"
154 and "jump-to-nav" accessibility links. To this end, the "jquery.mw-jump"
155 is no longer loaded by default. The Vector and MonoBook skins have made a
156 minor change to implement the toggle feature with CSS instead. To restore
157 prior functionality, either explicitly load "jquery.mw-jump" in your skin
158 or refer to T195256 for details on how to make the same change.
159
160 === Deprecations in 1.32 ===
161 * Use of a StartProfiler.php file is deprecated in favour of placing
162 configuration in LocalSettings.php.
163 * HTMLForm::setSubmitProgressive() is deprecated. No need to call it. Submit
164 button is already marked as progressive.
165 * Skin::setupSkinUserCss() is deprecated. Adding of modules to load
166 has been centralised to Skin::getDefaultModules(), which is now capable
167 of queueing style modules as well.
168 * OutputPage::addModuleScripts() and ParserOutput::addModuleScripts are
169 deprecated. Use addModules() instead.
170 * Overriding SearchEngine::{searchText,searchTitle,searchArchiveTitle}
171 in extending classes is deprecated. Extend related doSearch* methods
172 instead.
173 * CollationFa has been removed completely as it's not needed anymore
174 * The following 'mediawiki.api' plugin modules were merged into mediawiki.api
175 and deprecated: mediawiki.api.category, mediawiki.api.edit,
176 mediawiki.api.login, mediawiki.api.options, mediawiki.api.parse,
177 mediawiki.api.upload, mediawiki.api.user, mediawiki.api.watch,
178 mediawiki.api.messages, and mediawiki.api.rollback.
179 * ApiBase::truncateArray() is deprecated. No replacement, as nothing is known
180 to use it.
181 * WatchAction::getUnwatchToken is deprecated. Use WatchAction::getWatchToken
182 with the 'unwatch' action parameter instead.
183 * IcuCollation::getICUVersion() is deprecated, as you can just use the PHP
184 constant INTL_ICU_VERSION directly in all versions that MediaWiki supports.
185 * Parser::fetchFile() is deprecated. Use ::fetchFileAndTitle() instead.
186 * The ApiQueryContributions class has been renamed to ApiQueryUserContribs.
187 * The XMPInfo, XMPReader, and XMPValidate classes have been deprecated in favor
188 of the namespaced classes provided by the wikimedia/xmp-reader library.
189 * Class CryptRand, everything in MWCryptRand except generateHex() and function
190 MediaWikiServices::getCryptRand() are deprecated, use random_bytes() to
191 generate cryptographically secure random byte sequences.
192
193 === Other changes in 1.32 ===
194 * …
195
196 == Compatibility ==
197 MediaWiki 1.32 requires PHP 7.0.0 or later. Although HHVM 3.18.5 or later is
198 supported, it is generally advised to use PHP 7.0.0 or later for long term
199 support.
200
201 MySQL/MariaDB is the recommended DBMS. PostgreSQL or SQLite can also be used,
202 but support for them is somewhat less mature. There is experimental support for
203 Oracle and Microsoft SQL Server.
204
205 The supported versions are:
206
207 * MySQL 5.5.8 or later
208 * PostgreSQL 9.2 or later
209 * SQLite 3.3.7 or later
210 * Oracle 9.0.1 or later
211 * Microsoft SQL Server 2005 (9.00.1399)
212
213 == Upgrading ==
214 1.32 has several database changes since 1.31, and will not work without schema
215 updates. Note that due to changes to some very large tables like the revision
216 table, the schema update may take quite long (minutes on a medium sized site,
217 many hours on a large site).
218
219 Don't forget to always back up your database before upgrading!
220
221 See the file UPGRADE for more detailed upgrade instructions, including
222 important information when upgrading from versions prior to 1.11.
223
224 For notes on 1.31.x and older releases, see HISTORY.
225
226 == Online documentation ==
227 Documentation for both end-users and site administrators is available on
228 MediaWiki.org, and is covered under the GNU Free Documentation License (except
229 for pages that explicitly state that their contents are in the public domain):
230
231 https://www.mediawiki.org/wiki/Special:MyLanguage/Documentation
232
233 == Mailing list ==
234 A mailing list is available for MediaWiki user support and discussion:
235
236 https://lists.wikimedia.org/mailman/listinfo/mediawiki-l
237
238 A low-traffic announcements-only list is also available:
239
240 https://lists.wikimedia.org/mailman/listinfo/mediawiki-announce
241
242 It's highly recommended that you sign up for one of these lists if you're
243 going to run a public MediaWiki, so you can be notified of security fixes.
244
245 == IRC help ==
246 There's usually someone online in #mediawiki on irc.freenode.net.