Return to LESS multiple value escape mechanism to prevent invalid output
[lhc/web/wiklou.git] / RELEASE-NOTES-1.33
1 == MediaWiki 1.33 ==
2
3 THIS IS NOT A RELEASE YET
4
5 MediaWiki 1.33 is an alpha-quality branch and is not recommended for use in
6 production.
7
8 === Configuration changes in 1.33 ===
9
10 ==== New configuration ====
11 * $wgEnablePartialBlocks – This enables the Partial Blocks feature, which gives
12 accounts with block permissions the ability to block users, IPs, and IP ranges
13 from editing specific pages, while allowing them to edit the rest of the wiki.
14 * $wgMediaInTargetLanguage – whether multilingual images should be dispalyed in
15 the current parse language where available.
16
17 ==== Changed configuration ====
18 * Some external link searches will not work correctly until update.php (or
19 refreshExternallinksIndex.php) is run. These include searches for links using
20 IP addresses, internationalized domain names, and possibly mailto links.
21 * (T193868) $wgChangeTagsSchemaMigrationStage — This temporary setting, added in
22 MediaWiki 1.32, now defaults to MIGRATION_NEW instead of MIGRATION_WRITE_BOTH.
23 * …
24
25 ==== Removed configuration ====
26 * (T199334) $wgTagStatisticsNewTable — This temporary setting, added in
27 MediaWiki 1.32, has now been removed. When loading Special:Tags, MediaWiki
28 will now always use the `change_tag_def` instead of the `change_tag` table.
29 * MediaWiki now always tidies user output, and most related
30 configuration has been removed. Thus $wgUseTidy, $wgTidyBin,
31 $wgTidyConf, $wgTidyOpts, $wgTidyInternal, and $wgDebugTidy, all
32 deprecated since 1.26, have now all been removed. The $wgTidyConfig
33 setting remains only for Remex experimental features or debugging.
34 * …
35
36 === New features in 1.33 ===
37 * (T96041) __EXPECTUNUSEDCATEGORY__ on a category page causes the category
38 to be hidden on Special:UnusedCategories.
39 * Add PasswordPolicy to check the password isn't in the large blacklist.
40 * The AuthManagerLoginAuthenticateAudit hook has a new parameter for
41 additional information about the authentication event.
42 * TextContent::getText() was introduced as a replacement for
43 Content::getNativeData() for text-based content models.
44 * …
45
46 === External library changes in 1.33 ===
47
48 ==== New external libraries ====
49 * Added wikimedia/password-blacklist 0.1.4.
50 * Added guzzlehttp/guzzle 6.3.3.
51 * …
52
53 ==== Changed external libraries ====
54 * Updated wikimedia/xmp-reader from 0.6.0 to 0.6.1.
55 * Updated wikimedia/scoped-callback from 2.0.0 to 3.0.0.
56 * Updated wikimedia/ip-set from 1.2.0 to 2.0.0.
57 * The deprecated IPSet\IPSet alias was removed, Wikimedia\IPSet must be
58 used instead.
59 * Updated qunitjs from 2.6.2 to 2.9.1.
60 * …
61
62 ==== Removed external libraries ====
63 * …
64
65 === Bug fixes in 1.33 ===
66 * (T164211) Special:UserRights could sometimes fail with a
67 "conflict detected" error when there weren't any conflicts.
68 * …
69
70 === Action API changes in 1.33 ===
71 * (T198913) Added 'ApiOptions' hook.
72 * The JSON formatversion=2 is no longer experimental.
73 * Internal API errors (those with code beginning "internal_api_error") will
74 include the exception class name in a data field named "errorclass".
75 * Class names are not guaranteed to remain stable, and in particular database
76 exceptions will now include the "Wikimedia\Rdbms\" prefix in the class name.
77 * The code including an exception class name is deprecated. In the future,
78 all internal errors will use code "internal_api_error".
79 * (T212356) When using action=delete on pages with many revisions, the module
80 may return a boolean-true 'scheduled' and no 'logid'. This signifies that the
81 deletion will be processed via the job queue.
82
83 === Action API internal changes in 1.33 ===
84 * A number of deprecated methods for API documentation, intended for overriding
85 by extensions, are no longer called by MediaWiki, and will emit deprecation
86 notices if your extension attempts to use them:
87 * ApiBase::getDescription() (deprecated in 1.25)
88 * ApiBase::getParamDescription() (deprecated in 1.25)
89 * ApiBase::getExamples() (deprecated in 1.25)
90 * ApiBase::getDescriptionMessage() (deprecated in 1.30)
91 Additionally, the 'APIGetDescription' and 'APIGetParamDescription' hooks have
92 been removed, as their only use was to let extensions override values returned
93 by getDescription() and getParamDescription(), respectively.
94 * API error codes may only contain ASCII letters, numbers, underscore, and
95 hyphen. Methods such as ApiBase::dieWithError() and
96 ApiMessageTrait::setApiCode() will throw an InvalidArgumentException if
97 passed a bad code.
98 * …
99
100 === Languages updated in 1.33 ===
101 MediaWiki supports over 350 languages. Many localisations are updated regularly.
102 Below only new and removed languages are listed, as well as changes to languages
103 because of Phabricator reports.
104
105 * (T203908) Added language support for Eastern Pwo (kjp).
106 * (T213717) Fixed a translation error on Goan Konkani (gom-deva) translations
107 for NS_TEMPLATE.
108
109 === Breaking changes in 1.33 ===
110 * The parameteter $lang in DifferenceEngine::setTextLanguage must be of type
111 Language. Other types are deprecated since 1.32.
112 * Skin::doEditSectionLink requires type Language for the parameter $lang.
113 The parameters $tooltip and $lang are mandatory. Omitting the parameters is
114 deprecated since 1.32.
115 * Language::truncate(), deprecated in 1.31, has been removed.
116 * UtfNormal, deprecated in 1.25, was removed. Use UtfNormal\Validator directly
117 instead.
118 * (T197179) In OOUI HTMLForm fields, the parameters 'notice', 'notice-messages',
119 and 'notice-message', which were deprecated in 1.32, were removed. Instead,
120 use 'help', 'help-message', and 'help-messages'.
121 * (T197179) HTMLFormField::getNotices(), deprecated in 1.32, was removed.
122 * The "Parsoid v1" compatibility mappings in ParsoidVirtualRESTService and
123 RestbaseVirtualRESTService, deprecated since 1.26, have been removed.
124 Use the RESTBase v1 or Parsoid v3 API instead.
125 * ParserOptions defaults 'tidy' to true now, since the untidy modes of the
126 parser are being deprecated and ParserOptions::getCanonicalOverrides()
127 has always been true at any rate.
128 * Support for disabling tidy and external tidy implementations has been removed.
129 This was deprecated in 1.32. The pure PHP Remex tidy implementation is now
130 used and no configuration is necessary.
131 * A number of deprecated methods for API documentation, intended for overriding
132 by extensions, are no longer called by MediaWiki, and will emit deprecation
133 notices if your extension attempts to use them:
134 * ApiBase::getDescription() (deprecated in 1.25)
135 * ApiBase::getParamDescription() (deprecated in 1.25)
136 * ApiBase::getExamples() (deprecated in 1.25)
137 * ApiBase::getDescriptionMessage() (deprecated in 1.30)
138 Additionally, the 'APIGetDescription' and 'APIGetParamDescription' hooks have
139 been removed, as their only use was to let extensions override values returned
140 by getDescription() and getParamDescription(), respectively.
141 * The authentication hooks 'AbortAutoAccount' 'AbortNewAccount', 'AbortLogin',
142 'LoginUserMigrated', 'UserCreateForm', and 'UserLoginForm', all deprecated by
143 the creation of AuthManager in 1.27, have been removed. This also means that
144 the FakeAuthTemplate and LoginForm classes are removed, that FakeAuthTemplate
145 is no longer passed into LoginSignupSpecialPage->getFieldDefinitions(), and
146 that LoginSignupSpecialPage->getBCFieldDefinitions() is removed.
147 * The 'jquery.localize' module, deprecated in 1.32, has been removed. Instead,
148 use 'jquery.i18n'.
149 * The hooks LanguageGetSpecialPageAliases and LanguageGetMagic, deprecated since
150 1.16, have now been removed. Instead, use $specialPageAliases or $magicWords
151 respectively in a $wgExtensionMessagesFiles file.
152 * The following methods of the Preferences class, deprecated in 1.31, have been
153 removed:
154 * getSaveBlacklist()
155 * loadPreferenceValues()
156 * getOptionFromUser()
157 * profilePreferences()
158 * skinPreferences()
159 * filesPreferences()
160 * datetimePreferences()
161 * renderingPreferences()
162 * editingPreferences()
163 * rcPreferences()
164 * watchlistPreferences()
165 * searchPreferences()
166 * miscPreferences()
167 * generateSkinOptions()
168 * getDateOptions()
169 * getImageSizes()
170 * getThumbSizes()
171 * validateSignature()
172 * cleanSignature()
173 * getTimezoneOptions()
174 * filterIntval()
175 * filterTimezoneInput()
176 * getTimeZoneList()
177 * mw.util.jsMessage(), deprecated in 1.20, was removed. Use mw.notify instead.
178 * (T61113) User::EDIT_TOKEN_SUFFIX was removed. It was deprecated since 1.27.
179
180 === Deprecations in 1.33 ===
181 * The configuration option $wgUseESI has been deprecated, and is expected
182 to be removed in a future release.
183 * The configuration option $wgSquidPurgeUseHostHeader has been deprecated,
184 and is expected to be removed in a future release.
185 * The configuration options $wgFixArabicUnicode and $wgFixMalayalamUnicode,
186 introduced in MW 1.17, have been deprecated. These fixes will always be
187 applied for Arabic and Malayalam in the future. Please enable these on
188 your local wiki (if you have them explicitly set to false) and run
189 maintenance/cleanupTitles.php to fix any existing page titles.
190 * The LegacyHookPreAuthenticationProvider class, deprecated since its creation
191 in 1.27 as part of the AuthManager re-write, now emits deprecation warnings.
192 This will help identify the issue if you added it to $wgAuthManagerConfig.
193 * wfSplitWikiId() is now deprecated. Cache key generation should have the wiki
194 domain ID as a key component and use makeGlobalKey().
195 * (T202094) Title::getUserCaseDBKey() is deprecated; instead, please use
196 Title::getDBKey(), which doesn't vary case.
197 * User::getPasswordValidity() is now deprecated. User::checkPasswordValidity()
198 returns the same information in a more useful format.
199 * For Linker::generateTOC() and Linker::tocList(), passing strings or booleans
200 as the $lang parameter was deprecated. The same applies to DummyLinker.
201 * The PasswordPolicy 'PasswordCannotBePopular' has been deprecated. To
202 follow best practices, it is reccommended to use 'PasswordNotInLargeBlacklist'
203 instead which blacklists 100,000 commonly used passwords.
204 * (T208862) Action::requiresUnblock() is now called from
205 Title::getUserPermissionsErrors() and Title::userCan(). Previously, the method
206 was only called in Action::checkCanExecute(). Actions should ensure that their
207 requiresUnblock() returns the proper result (the default is `true`).
208 * (T211608) The MediaWiki\Services namespace has been renamed to
209 Wikimedia\Services. The old name is still supported, but deprecated.
210 * (T155582) Content::getNativeData has been deprecated. Please use model-
211 specific getters, such as TextContent::getText().
212 * …
213
214 === Other changes in 1.33 ===
215 * (T208871) The hard-coded Google search form on the database error page was
216 removed.
217 * (T201747) Html::openElement() warns if given an element name wiht a space
218 in it.
219 * …
220
221 == Compatibility ==
222 MediaWiki 1.33 requires PHP 7.0.0 or later. Although HHVM 3.18.5 or later is
223 supported, it is generally advised to use PHP 7.0.0 or later for long term
224 support.
225
226 MySQL/MariaDB is the recommended DBMS. PostgreSQL or SQLite can also be used,
227 but support for them is somewhat less mature. There is experimental support for
228 Oracle and Microsoft SQL Server.
229
230 The supported versions are:
231
232 * MySQL 5.5.8 or later
233 * PostgreSQL 9.2 or later
234 * SQLite 3.3.7 or later
235 * Oracle 9.0.1 or later
236 * Microsoft SQL Server 2005 (9.00.1399)
237
238 == Upgrading ==
239 1.33 has several database changes since 1.32, and will not work without schema
240 updates. Note that due to changes to some very large tables like the revision
241 table, the schema update may take quite long (minutes on a medium sized site,
242 many hours on a large site).
243
244 Don't forget to always back up your database before upgrading!
245
246 See the file UPGRADE for more detailed upgrade instructions, including
247 important information when upgrading from versions prior to 1.11.
248
249 For notes on 1.32.x and older releases, see HISTORY.
250
251 == Online documentation ==
252 Documentation for both end-users and site administrators is available on
253 MediaWiki.org, and is covered under the GNU Free Documentation License (except
254 for pages that explicitly state that their contents are in the public domain):
255
256 https://www.mediawiki.org/wiki/Special:MyLanguage/Documentation
257
258 == Mailing list ==
259 A mailing list is available for MediaWiki user support and discussion:
260
261 https://lists.wikimedia.org/mailman/listinfo/mediawiki-l
262
263 A low-traffic announcements-only list is also available:
264
265 https://lists.wikimedia.org/mailman/listinfo/mediawiki-announce
266
267 It's highly recommended that you sign up for one of these lists if you're
268 going to run a public MediaWiki, so you can be notified of security fixes.
269
270 == IRC help ==
271 There's usually someone online in #mediawiki on irc.freenode.net.