Add mechanism for temporary user rights
[lhc/web/wiklou.git] / RELEASE-NOTES-1.34
1 = MediaWiki 1.34 =
2
3 == MediaWiki 1.34.0-PRERELEASE ==
4
5 THIS IS NOT A RELEASE YET
6
7 MediaWiki 1.34 is an alpha-quality development branch, and is not recommended
8 for use in production.
9
10 == Upgrading notes for 1.34 ==
11 1.34 has several database changes since 1.33, and will not work without schema
12 updates. Note that due to changes to some very large tables like the revision
13 table, the schema update may take quite long (minutes on a medium sized site,
14 many hours on a large site).
15
16 Don't forget to always back up your database before upgrading!
17
18 See the file UPGRADE for more detailed upgrade instructions, including
19 important information when upgrading from versions prior to 1.11.
20
21 Some specific notes for MediaWiki 1.34 upgrades are below:
22
23 * …
24
25 For notes on 1.33.x and older releases, see HISTORY.
26
27 === Configuration changes for system administrators in 1.34 ===
28
29 ==== New configuration ====
30 * $wgAllowExternalReqID (T201409) - This configuration setting controls whether
31 Mediawiki accepts the request ID set by the incoming request via the
32 `X-Request-Id` header. If set to `true`, that value will be used throughout
33 the code as the request identificator. Otherwise, the sent header will be
34 ignored and the request ID will either be taken from Apache's mod_unique
35 module or will be generated by Mediawiki itself (depending on the set-up).
36 * $wgEnableSpecialMute (T218265) - This configuration controls whether
37 Special:Mute is available and whether to include a link to it on emails
38 originating from Special:Email.
39
40 ==== Changed configuration ====
41 * $wgUseCdn, $wgCdnServers, $wgCdnServersNoPurge, and $wgCdnMaxAge – These four
42 CDN-related config variables have been renamed from being specific to Squid –
43 they were previously $wgUseSquid, $wgSquidServers, $wgSquidServersNoPurge, and
44 $wgSquidMaxage respectively. This aligns them with the related existing
45 variable $wgCdnMaxageLagged. The previous configuration variable names are
46 deprecated, but will be used as the fall back if they are still set.
47 Note that wgSquidPurgeUseHostHeader has not been renamed, as it is deprecated.
48 * (T27707) File type checks for image uploads have been relaxed to allow files
49 containing some HTML markup in metadata. As a result, the $wgAllowTitlesInSVG
50 setting is no longer applied and is now always true. Note that MSIE 7 may
51 still be able to misinterpret certain malformed PNG files as HTML.
52 * Introduced $wgVerifyMimeTypeIE to allow disabling the MSIE 6/7 file type
53 detection heuristic on upload, which is more conservative than the checks
54 that were changed above.
55 * $wgSkipSkin — Setting this instead of $wgSkipSkins, deprecated in 1.23, is now
56 hard-deprecated.
57 * $wgLocalInterwiki — Setting this instead of $wgLocalInterwikis, deprecated in
58 1.23, is now hard-deprecated.
59 * …
60
61 ==== Removed configuration ====
62 * $wgWikiDiff2MovedParagraphDetectionCutoff — If you still want a custom change
63 size threshold, please specify in php.ini, using the configuration variable
64 wikidiff2.moved_paragraph_detection_cutoff.
65 * $wgDebugPrintHttpHeaders - The default of including HTTP headers in the
66 debug log channel is no longer configurable. The debug log itself remains
67 configurable via $wgDebugLogFile.
68
69 === New user-facing features in 1.34 ===
70 * Special:Mute has been added as a quick way for users to block unwanted emails
71 from other users originating from Special:EmailUser.
72
73 === New developer features in 1.34 ===
74 * The ImgAuthModifyHeaders hook was added to img_auth.php to allow modification
75 of headers in private wikis.
76 * Language::formatTimePeriod now supports the new 'avoidhours' option to output
77 strings like "5 days ago" instead of "5 days 13 hours ago".
78
79 === External library changes in 1.34 ===
80
81 ==== New external libraries ====
82 * …
83
84 ==== Changed external libraries ====
85 * Updated Mustache from 1.0.0 to v3.0.1.
86 * Updated OOUI from v0.31.3 to v0.33.2.
87 * Updated composer/semver from 1.4.2 to 1.5.0.
88 * Updated composer/spdx-licenses from 1.4.0 to 1.5.1 (dev-only).
89 * Updated mediawiki/codesniffer from 25.0.0 to 26.0.0 (dev-only).
90 * Updated cssjanus/cssjanus from 1.2.1 to 1.3.0.
91 * Updated wikimedia/at-ease from 1.2.0 to 2.0.0.
92 * Updated wikimedia/remex-html from 2.0.1 to 2.0.3.
93 * Updated monolog/monolog from 1.22.1 to 1.24.0 (dev-only).
94 * Updated wikimedia/object-factory from 1.0.0 to 2.1.0.
95 * Updated wikimedia/timestamp from 2.2.0 to 3.0.0.
96 * Updated wikimedia/xmp-reader from 0.6.2 to 0.6.3.
97 * Updated mediawiki/mediawiki-phan-config from 0.6.0 to 0.6.1 (dev-only).
98 * …
99
100 ==== Removed external libraries ====
101 * The jquery.async module, deprecated in 1.33, was removed.
102 * …
103
104 === Bug fixes in 1.34 ===
105 * (T222529) If a log entry or page revision is recorded in the database with an
106 empty username, attempting to display it will log an error and return a "no
107 username available" to the user instead of silently displaying nothing or
108 invalid links.
109
110 === Action API changes in 1.34 ===
111 * The 'recenteditcount' response property from action=query list=allusers,
112 deprecated in 1.25, has been removed.
113
114 === Action API internal changes in 1.34 ===
115 * …
116
117 === Languages updated in 1.34 ===
118 MediaWiki supports over 350 languages. Many localisations are updated regularly.
119 Below only new and removed languages are listed, as well as changes to languages
120 because of Phabricator reports.
121
122 * (T152908) Added language support for N'Ko (nqo).
123
124 === Breaking changes in 1.34 ===
125 * The global functions wfSuppressWarnings and wfRestoreWarnings, deprecated in
126 1.26, have been removed. Use Wikimedia\AtEase\AtEase::suppressWarnings() and
127 Wikimedia\AtEase\AtEase::restoreWarnings() directly.
128 * Preferences class, deprecated in 1.31, has been removed.
129 * The following parts of code, deprecated in 1.32, were removed in favor of
130 built-in PHP functions:
131 * CryptRand class
132 * CryptRand service
133 * Functions of the MWCryptRand class: singleton(), wasStrong() and generate().
134 * Language::setCode, deprecated in 1.32, was removed. Use Language::factory to
135 create a new Language object with a different language code.
136 * MWNamespace::clearCaches() has been removed. So has the $rebuild parameter
137 to MWNamespace::getCanonicalNamespaces(), which was deprecated since 1.31.
138 Instead, reset services, such as by calling $this->overrideMwServices() (if
139 your test extends MediaWikiTestCase). Services will generally not pick up
140 configuration changes from after they were created, so you must reset
141 services after any configuration change. Even if your code works now, it is
142 likely to break in future versions as more code is moved to services.
143 * The ill-defined "DatabaseOraclePostInit" hook has been removed.
144 * PreferencesFormLegacy and PreferencesForm classes, deprecated in 1.32, have
145 been removed.
146 * ObjectFactory class, deprecated in 1.31, has been removed.
147 * HWLDFWordAccumudlator class, deprecated in 1.28, has been removed.
148 * XMPInfo, XMPReader and XMPValidate, deprecated in 1.32, have been removed.
149 * The RedirectSpecialPage::execute method could sometimes return a Title object.
150 This behavior was removed, and the method now matches the parent signature
151 (SpecialPage::execute) which is to return HTML string or void.
152 To obtain the destination title, use RedirectSpecialPage::getRedirect.
153 * The 'recenteditcount' response property from action API action=query
154 list=allusers, deprecated in 1.25, has been removed.
155 * SearchEngine::userNamespaces(), SearchEngine::namespacesAsText(),
156 SearchEngine::create(), SearchEngine::getSearchTypes() and
157 SearchEngine::getNearMatch(), methods deprecated in 1.27, have been removed.
158 * FileRepo::streamFile(), deprecated in 1.26, has been removed.
159 * User::randomPassword() method, deprecated in 1.27, have been removed.
160 * MWNamespace::canTalk(), deprecated in 1.30, have been removed.
161 * Parser class property $mUniqPrefix, deprecated in 1.26, has been removed.
162 * wfArrayFilter() and wfArrayFilterByKey(), deprecated in 1.32, have been
163 removed.
164 * wfMakeUrlIndexes() function, deprecated in 1.33, have been removed.
165 * Method signatures in WatchedItemQueryServiceExtension have changed from taking
166 User objects to taking UserIdentity objects. Extensions implementing this
167 interface need to be changed accordingly.
168 * User::getGroupPage() and ::makeGroupLinkHTML(), deprecated in 1.29, have been
169 removed. Use UserGroupMembership::getGroupPage and ::getLink instead.
170 * User::makeGroupLinkWiki(), deprecated in 1.29, has been removed. Use
171 UserGroupMembership::getLink() instead.
172 * SavepointPostgres, deprecated in 1.31, has been removed.
173 * OutputPage::enableSectionEditLinks(), OutputPage::sectionEditLinksEnabled(),
174 ParserOptions::getEditSection(), ParserOptions::setEditSection(), and
175 ParserOutput::getEditSectionTokens, ::getTOCEnabled, ::setEditSectionTokens,
176 and ::setTOCEnabled, deprecated in 1.31, have been removed.
177 * EditPage::safeUnicodeInput() and ::safeUnicodeOutput(), deprecated in 1.30,
178 have been removed.
179 * Four methods in OutputPage, deprecated in 1.32, have been removed. You should
180 use OutputPage::showFatalError or throw a FatalError instead. The methods are
181 ::showFileCopyError(), ::showFileRenameError(), ::showFileDeleteError(), and
182 ::showFileNotFoundError().
183 * ApiBase::truncateArray(), deprecated in 1.32, has been removed.
184 * IcuCollation::getICUVersion(), deprecated in 1.32, has been removed. Use PHP's
185 INTL_ICU_VERSION constant directly.
186 * HTMLForm::setSubmitProgressive(), deprecated in 1.32, has been removed.
187 * ResourceLoaderStartUpModules::getStartupModules() and ::getLegacyModules(),
188 both deprecated in 1.32, have been removed.
189 * BaseTemplate::msgHtml() and QuickTemplate::msgHtml(), deprecated in 1.32, have
190 been removed. Use ->msg() or ->getMsg() instead.
191 * WatchAction::getUnwatchToken(), deprecated in 1.32, has been removed. Instead,
192 use WatchAction::getWatchToken() with action 'unwatch' directly.
193 * Language::initEncoding(), ::recodeForEdit(), and recodeInput(), deprecated in
194 1.28, have been removed.
195 * PageArchive::getTextFromRow(), ::listAllPages(), and ::getLastRevisionText(),
196 deprecated in 1.32, have been removed.
197 * OutputPage::getModuleScripts(), ParserOutput::getModuleScripts(), deprecated
198 in 1.33, have been removed.
199 * User::getPasswordValidity(), deprecated in 1.33, has been removed.
200 * ApiQueryBase::prepareUrlQuerySearchString(), deprecated in 1.33, has been
201 removed.
202 * ChangeTags::purgeTagUsageCache(), deprecated in 1.33, has been removed.
203 * JobQueueGroup::pushLazyJobs(), deprecated in 1.33, has been removed.
204 * MediaWikiTestCase::stashMwGlobals(), deprecated in 1.32, has been removed.
205 * SearchEngine::transformSearchTerm(), deprecated in 1.32, has been removed.
206 * The Block typehint only refers to blocks stored in the database. It should be
207 updated to AbstractBlock in cases where any type of block could be expected.
208 * FileRepoStatus, deprecated in 1.25, has been removed.
209 * The LegacyHookPreAuthenticationProvider class, deprecated since its creation
210 in 1.27, has been removed.
211 * IP::isValidBlock(), deprecated in 1.30, has been removed.
212 * WikiPage::prepareContentForEdit now doesn't accept an integer for $revision,
213 was deprecated in 1.25.
214 * The jquery.byteLength module, deprecated in 1.31, was removed.
215 Use the mediawiki.String module instead.
216 * mw.language.specialCharacters, deprecated in 1.33, has been removed.
217 Use require( 'mediawiki.language.specialCharacters' ) instead.
218 * EditPage::submit(), deprecated in 1.29, has been removed. Use $this->edit()
219 directly.
220 * HTMLForm::getErrors(), deprecated in 1.28, has been removed. Use
221 getErrorsOrWarnings() instead.
222 * SpecialPage::getTitle(), deprecated in 1.23, has been removed. Use
223 SpecialPage::getPageTitle() instead.
224 * jquery.ui.effect-bounce, jquery.ui.effect-explode, jquery.ui.effect-fold
225 jquery.ui.effect-pulsate, jquery.ui.effect-slide, jquery.ui.effect-transfer,
226 which are no longer used, have now been removed.
227 * SpecialEmailUser::validateTarget(), ::getTarget() without a sender/user
228 specified, deprecated in 1.30, have been removed.
229 * BufferingStatsdDataFactory::getBuffer(), deprecated in 1.30, has been removed.
230 * The constant DB_SLAVE, deprecated in 1.28, has been removed. Use DB_REPLICA.
231 * The constants NS_IMAGE and NS_IMAGE_TALK, deprecated in 1.14, have been
232 removed. Use NS_FILE and NS_FILE_TALK respectively.
233 * Replacer, DoubleReplacer, HashtableReplacer and RegexlikeReplacer
234 (deprecated in 1.32) have been removed. Closures should be used instead.
235 * OutputPage::addWikiText(), ::addWikiTextWithTitle(), ::addWikiTextTitleTidy(),
236 ::addWikiTextTidy(), ::addWikiTextTitle(), deprecated in 1.32, have been
237 removed.
238 * The $wgUseKeyHeader configuration option and the OutputPage::getKeyHeader()
239 method, deprecated in 1.32, have been removed.
240 * WebInstallerOutput::addWikiText(), deprecated in 1.32, has been removed.
241 * Parser::fetchFile(), deprecated in 1.32, has been removed. Use the method
242 Parser::fetchFileAndTitle() instead.
243 * The global function wfBCP47, deprecated in 1.31, has been removed.
244 * wfCountDown() function, deprecated in 1.31, has been removed. Use
245 \Maintenance::countDown() method instead.
246 * OutputPage::wrapWikiMsg() no longer accepts an options parameter. This was
247 deprecated since 1.20.
248 * Skin::outputPage() no longer accepts a context. This was deprecated in 1.20.
249 * Linker::link() no longer accepts a string for the query array, as was
250 deprecated in 1.20.
251 * PrefixSearch::titleSearch(), deprecated in 1.23, has been removed. Use the
252 SearchEngine::defaultPrefixSearch or ::completionSearch() methods instead.
253 * The UserRights hook, deprecated in 1.26, has been removed. Instead, use the
254 UserGroupsChanged hook.
255 * Skin::getDefaultInstance(), deprecated in 1.27, has been removed. Get the
256 instance from MediaWikiServices instead.
257 * The UserLoadFromSession hook, deprecated in 1.27, has been removed.
258 * The wfResetSessionID global function, deprecated in 1.27, has been removed.
259 Use MediaWiki\Session\SessionManager instead.
260 * The wfGetLBFactory global function, deprecated in 1.27, has been removed.
261 Use MediaWikiServices::getInstance()->getDBLoadBalancerFactory().
262 * The internal method OutputPage->addScriptFile() will no longer silently drop
263 calls that use an invalid path (i.e., something other than an absolute path,
264 protocol-relative URL, or full scheme URL), and will instead pass them to the
265 client where they will likely 404. This usage was deprecated in 1.24.
266 * Database::reportConnectionError, deprecated in 1.32, has been removed.
267 * APIEditBeforeSave hook, deprecated in 1.28, has been removed. Please see
268 EditFilterMergedContent hook for an alternative way to use this feature.
269 * API module methods getDescription(), getParamDescription(), & getExamples(),
270 all deprecated in 1.25 and ignored, have been removed.
271 * The API module method getDescriptionMessage(), deprecated in 1.30, has been
272 removed.
273 * The JavaScript global variable wgLoadScript has been removed. Use
274 mw.util.wikiScript( 'load' ) instead.
275 * ResourceLoader no longer creates the 'mw.legacy' placeholder object. It has
276 been unused since 1.16 and was deprecated in 1.22. To deprecate a property
277 in JavaScript, use mw.log.deprecate() instead.
278 * The 'user.groups' module, deprecated in 1.28, was removed.
279 Use the 'user' module instead.
280 * The ability to override User::$mRights has been removed. Use
281 PermissionManager::addTemporaryUserRights() instead.
282 * Previously, when iterating ResultWrapper with foreach() or a similar
283 construct, the range of the index was 1..numRows. This has been fixed to be
284 0..(numRows-1).
285 * The ChangePasswordForm hook, deprecated in 1.27, has been removed. Use the
286 AuthChangeFormFields hook or security levels instead.
287 * WikiMap::getWikiIdFromDomain(), deprecated in 1.33, has been removed.
288 Use WikiMap::getWikiIdFromDbDomain() instead.
289 * The config variables $wgHtml5, $wgJsMimeType, and $wgXhtmlDefaultNamespace,
290 which were deprecated and ignored by core since 1.22, are no longer set to any
291 value, and SkinTemplate no longer emits a 'jsmimetype' key. Any extensions not
292 updated since 2013 to cope with this deprecation may now break.
293 * (T222637) Passing ResourceLoaderModule objects to ResourceLoader::register()
294 or $wgResourceModules is no longer supported.
295 Use the 'class' or 'factory' option of the array format instead.
296 * The parameter $lang of the functions generateTOC and tocList in Linker and
297 DummyLinker must be in type Language when present. Other types are
298 deprecated since 1.33.
299 * …
300
301 === Deprecations in 1.34 ===
302 * The MWNamespace class is deprecated. Use NamespaceInfo.
303 * ExtensionRegistry->load() is deprecated, as it breaks dependency checking.
304 Instead, use ->queue().
305 * User::isBlocked() is deprecated since it does not tell you if the user is
306 blocked from editing a particular page. Use User::getBlock() or
307 PermissionManager::isBlockedFrom() or PermissionManager::userCan() instead.
308 * User::isLocallyBlockedProxy and User::inDnsBlacklist are deprecated and moved
309 to the BlockManager as private helper methods.
310 * User::isDnsBlacklisted is deprecated. Use BlockManager::isDnsBlacklisted
311 instead.
312 * The Config argument to ChangesListSpecialPage::checkStructuredFilterUiEnabled
313 is deprecated. Pass only the User argument.
314 * WatchedItem::getUser is deprecated. Use getUserIdentity.
315 * Passing a Title as the first parameter to the getTimestampById method of
316 RevisionStore is deprecated. Omit it, passing only the remaining parameters.
317 * Title::getPreviousRevisionId and Title::getNextRevisionId are deprecated. Use
318 RevisionLookup::getPreviousRevision and RevisionLookup::getNextRevision.
319 * The Title parameter to RevisionLookup::getPreviousRevision and
320 RevisionLookup::getNextRevision is deprecated and should be omitted.
321 * MWHttpRequest::factory is deprecated. Use HttpRequestFactory.
322 * The Http class is deprecated. For the request, get, and post methods, use
323 HttpRequestFactory. For isValidURI, use MWHttpRequest::isValidURI. For
324 getProxy, use (string)$wgHTTPProxy. For createMultiClient, construct a
325 MultiHttpClient directly.
326 * Http::$httpEngine is deprecated and has no replacement. The default 'guzzle'
327 engine will eventually be made the only engine for HTTP requests.
328 * RepoGroup::singleton(), RepoGroup::destroySingleton(),
329 RepoGroup::setSingleton(), wfFindFile(), and wfLocalFile() are all
330 deprecated. Use MediaWikiServices instead.
331 * The getSubjectPage, getTalkPage, and getOtherPage of Title are deprecated.
332 Use NamespaceInfo's getSubjectPage, getTalkPage, and getAssociatedPage.
333 * MWMessagePack class, no longer used, has been deprecated in 1.34.
334 * The Block class is separated into DatabaseBlock (for blocks stored in the
335 database), and SystemBlock (for temporary blocks created by the system).
336 SystemBlock should be used when creating any temporary blocks. Block is
337 a deprecated alias for DatabaseBlock.
338 * Parser::$mConf is deprecated. It will be removed entirely in a later version.
339 Some context can be found at T224165.
340 * Constructing Parser directly is deprecated. Obtain one from ParserFactory.
341 * Title::moveSubpages is deprecated. Use MovePage::moveSubpages or
342 MovePage::moveSubpagesIfAllowed.
343 * The MWNamespace class is deprecated. Use MediaWikiServices::getNamespaceInfo.
344 * (T62260) Hard deprecate Language::getExtraUserToggles() method.
345 * Language::viewPrevNext function is deprecated, use
346 PrevNextNavigationRenderer::buildPrevNextNavigation instead
347 * User::trackBlockWithCookie and DatabaseBlock::clearCookie are deprecated. Use
348 BlockManager::trackBlockWithCookie and BlockManager::clearCookie instead.
349 * DatabaseBlock::setCookie, DatabaseBlock::getCookieValue,
350 DatabaseBlock::getIdFromCookieValue and AbstractBlock::shouldTrackWithCookie
351 are moved to internal helper methods for BlockManager::trackBlockWithCookie.
352 * ResourceLoaderContext::getConfig and ResourceLoaderContext::getLogger have
353 been deprecated. Inside ResourceLoaderModule subclasses, use the local methods
354 instead. Elsewhere, use the methods from the ResourceLoader class.
355 * The Preprocessor_DOM implementation has been deprecated. It will be
356 removed in a future release. Use the Preprocessor_Hash implementation
357 instead.
358 * Sanitizer::attributeWhitelist() and Sanitizer::setupAttributeWhitelist()
359 have been deprecated; they will be made private in the future.
360 * SearchResult::termMatches() method is deprecated. It was unreliable because
361 only populated by few search engine implementations. Use
362 SqlSearchResult::getTermMatches() if really needed.
363 * SearchResult::getTextSnippet( $terms ) the $terms param is being deprecated
364 and should no longer be passed. Search engine implemenations should be
365 responsible for carrying relevant information needed for highlighting with
366 their own SearchResultSet/SearchResult sub-classes.
367 * SearchEngine::$searchTerms protected field is deprecated. Moved to
368 SearchDatabase.
369 * The use of the $terms param in the ShowSearchHit and ShowSearchHitTitle
370 hooks is highly discouraged as it's only populated by SearchDatabase search
371 engines.
372 * Skin::escapeSearchLink() is deprecated. Use Skin::getSearchLink() or the skin
373 template option 'searchaction' instead.
374 * LoadBalancer::haveIndex() and LoadBalancer::isNonZeroLoad() have
375 been deprecated.
376 * User::getRights() and User::$mRights have been deprecated. Use
377 PermissionManager::getUserPermissions() instead.
378 * The LocalisationCacheRecache hook no longer allows purging of message blobs
379 to be prevented. Modifying the $purgeBlobs parameter now has no effect.
380
381 === Other changes in 1.34 ===
382 * …
383
384 == Compatibility ==
385 MediaWiki 1.34 requires PHP 7.0.13 or later. Although HHVM 3.18.5 or later is
386 supported, it is generally advised to use PHP 7.0.13 or later for long term
387 support.
388
389 MySQL/MariaDB is the recommended DBMS. PostgreSQL or SQLite can also be used,
390 but support for them is somewhat less mature. There is experimental support for
391 Oracle and Microsoft SQL Server.
392
393 The supported versions are:
394
395 * MySQL 5.5.8 or later
396 * PostgreSQL 9.2 or later
397 * SQLite 3.8.0 or later
398 * Oracle 9.0.1 or later
399 * Microsoft SQL Server 2005 (9.00.1399)
400
401 == Online documentation ==
402 Documentation for both end-users and site administrators is available on
403 MediaWiki.org, and is covered under the GNU Free Documentation License (except
404 for pages that explicitly state that their contents are in the public domain):
405
406 https://www.mediawiki.org/wiki/Special:MyLanguage/Documentation
407
408 == Mailing list ==
409 A mailing list is available for MediaWiki user support and discussion:
410
411 https://lists.wikimedia.org/mailman/listinfo/mediawiki-l
412
413 A low-traffic announcements-only list is also available:
414
415 https://lists.wikimedia.org/mailman/listinfo/mediawiki-announce
416
417 It's highly recommended that you sign up for one of these lists if you're
418 going to run a public MediaWiki, so you can be notified of security fixes.
419
420 == IRC help ==
421 There's usually someone online in #mediawiki on irc.freenode.net.