Segregate right to edit sitewide CSS/JS
[lhc/web/wiklou.git] / RELEASE-NOTES-1.32
1 == MediaWiki 1.32 ==
2
3 THIS IS NOT A RELEASE YET
4
5 MediaWiki 1.32 is an alpha-quality branch and is not recommended for use in
6 production.
7
8 === Configuration changes in 1.32 ===
9 * (T115414) The $wgEnableAPI and $wgEnableWriteAPI settings, deprecated in 1.31,
10 have been removed.
11 * The $wgUseAjax setting, deprecated in 1.31, is now ignored.
12 * The $wgSiteSupportPage setting, unused since 1.5, was removed.
13 * The $wgBrowserBlacklist setting, deprecated in 1.30, was removed.
14 * The default quality of JPEG thumbnails generated by GD was reduced from 95 to
15 80. The quality of JPEG thumbnails is now configurable through the new setting
16 $wgJpegQuality (default 80). This aligns the quality to what ImageMagick uses.
17 * $wgExperimentalHtmlIds, deprecated since 1.30, has been removed. The
18 'html5-legacy' value for $wgFragmentMode is no longer accepted.
19 * The experimental Html5Internal and Html5Depurate tidy drivers were removed.
20 RemexHtml, which is the default, should be used instead.
21 * (T135963) You can now define a Content Security Policy for your wiki. This
22 adds a defense-in-depth feature to stop an attacker who has found a bug in
23 the parser allowing them to insert malicious attributes. Disabled by default,
24 you can configure this via $wgCSPHeader and $wgCSPReportOnlyHeader.
25 * New configuration variable has been added: $wgCookieSetOnIpBlock.
26 This determines whether to set a cookie when an IP user is blocked. Doing so
27 means that a blocked user, even after moving to a new IP address, will still
28 be blocked.
29 * The archive table's ar_rev_id field is now unique.
30 * Special:BotPasswords now requires reauthentication.
31 * (T194414) The default watchlist view time has been increased from 3 to 7 days.
32 * The right to edit sitewide Javascript (e.g. MediaWiki:Common.js), CSS or JSON
33 was separated from 'editinterface' and is available under
34 'editsitejs'/'editsitecss'/'editsitejson'. Having 'editinterface' is still
35 necessary to edit such pages.
36 * A new user group, 'interface-admin', is added for controlling access to
37 sitewide CSS/JS (and editing other users' CSS/JS). No other group has
38 'editsitecss', 'editusercss', 'editsitejs' or 'edituserjs' by default.
39 * A new grant group, 'editsiteconfig', is added for granting the above rights.
40
41 === New features in 1.32 ===
42 * (T112474) Generalized the ResourceLoader mechanism for overriding modules
43 using a particular page during edit previews.
44 * (T12331) You can now log page creation events by setting $wgPageCreationLog
45 to true.
46 * Added 'ApiParseMakeOutputPage' hook.
47 * (T174313) Added checkbox on Special:ListUsers to display only users in
48 temporary user groups.
49 * (T152462) A cookie can now be set when an IP user is blocked to track that
50 user if they move to a new IP address. This is disabled by default.
51 * (T194950) Added 'ApiMaxLagInfo' hook.
52 * SpecialPage::checkLoginSecurityLevel() will now preserve POST data when
53 reauthenticating.
54 * FormSpecialPage::execute() will now call checkLoginSecurityLevel() if
55 getLoginSecurityLevel() returns non-false.
56 * The 'ImageBeforeProduceHTML' hook is now passed three new parameters, $parser,
57 &$query and &$widthOption, allowing extensions even finer control over the
58 resulting HTML code.
59 * Added new 'ArticleShowPatrolFooter' hook, which allows extensions to determine
60 if the [mark as patrolled] link should be shown at the footer of patrollable
61 pages.
62 * The array of hidden options ($opts) passed to the 'SpecialSearchPowerBox' hook
63 is now passed by reference, allowing extensions to modify or even unset it.
64 * Added new 'OutputPageAfterGetHeadLinksArray' hook, allowing extensions to
65 modify the return value of OutputPage#getHeadLinksArray in order to add,
66 remove or otherwise alter the elements to be output in the page <head>.
67
68 === External library changes in 1.32 ===
69 * …
70
71 ==== Upgraded external libraries ====
72 * Updated QUnit from 2.4.0 to 2.6.0.
73 * Updated wikimedia/scoped-callback from 1.0.0 to 2.0.0.
74 ** ScopedCallback objects can no longer be serialized.
75 * Updated wikimedia/wrappedstring from 2.3.0 to 3.0.1.
76
77 ==== New external libraries ====
78 * Added wikimedia/xmp-reader 0.5.1
79 * …
80
81 ==== Removed and replaced external libraries ====
82 * …
83
84 === Bug fixes in 1.32 ===
85 * SpecialPage::execute() will now only call checkLoginSecurityLevel() if
86 getLoginSecurityLevel() returns non-false.
87
88 === Action API changes in 1.32 ===
89 * Added templated parameters.
90 * A module can define a templated parameter like "{fruit}-quantity", where
91 the actual parameters recognized correspond to the values of a multi-valued
92 parameter. Then clients can make requests like
93 "fruits=apples|bananas&apples-quantity=1&bananas-quantity=5".
94 * action=paraminfo will return templated parameter definitions separately
95 from normal parameters. All parameter definitions now include an "index"
96 key to allow clients to maintain parameter ordering when merging normal and
97 templated parameters.
98 * It is now an error to submit too many values for a multi-valued parameter.
99 This has generated a warning since MediaWiki 1.14.
100 * Assertion failures from the 'assert' and 'assertuser' parameters will no
101 longer use the action module's custom response format, for the few modules
102 that use custom formatters that handle errors.
103 * (T198935) User list preferences such as `email-blacklist` and similar
104 extension preferences are no longer represented as arrays when returned by
105 action=query&meta=userinfo&uiprop=options.
106
107 === Action API internal changes in 1.32 ===
108 * Added 'ApiParseMakeOutputPage' hook.
109 * Parameter names may no longer contain '{' or '}', as these are now used for
110 templated parameters.
111 * (T194950) Added 'ApiMaxLagInfo' hook.
112
113 === Languages updated in 1.32 ===
114 MediaWiki supports over 350 languages. Many localisations are updated regularly.
115 Below only new and removed languages are listed, as well as changes to languages
116 because of Phabricator reports.
117
118 * (T193566) Added language support for Ambonese Malay (abs).
119 * (T194047) Added language support for Shawiya, Latin script (shy-latn).
120 * (T195940) Added language support for Batak Mandailing (btm).
121 * (T137491) Added language support for Standard Moroccan Amazigh (zgh).
122 * (T198132) Added language support for Manipuri (mni).
123
124 === Breaking changes in 1.32 ===
125 * $wgRequestTime, deprecated in 1.25, was removed. Use
126 $_SERVER['REQUEST_TIME_FLOAT'] or WebRequest::getElapsedTime() instead.
127 * The MediaWikiI18N class, deprecated in 1.31, was removed.
128 * QuickTemplate::setTranslator(), deprecated in 1.31, was removed. Use
129 Skin::msg() instead.
130 * wfInitShellLocale(), deprecated in 1.30, was removed.
131 * wfShellExecDisabled(), deprecated in 1.30, was removed.
132 * The type string for the parameter $lang of DateFormatter::getInstance,
133 deprecated in 1.31, was removed.
134 * The EDIT_TOKEN_SUFFIX constant deprecated in 1.27, was removed. Use
135 MediaWiki\Session\Token::SUFFIX instead.
136 * EditPage::isOouiEnabled() deprecated in 1.30, was removed.
137 * mw.util.wikiGetlink(), deprecated in 1.23, was removed. Use mw.util.getUrl()
138 instead.
139 * (T61113) The following methods and constants from the Revision class, which
140 were deprecated in 1.25, have now been removed:
141 * Revision::getRawUser()
142 * Revision::getRawUserText()
143 * Revision::getRawComment()
144 * window.gM() from mediawiki.jqueryMsg, deprecated in 1.23, was removed. Use
145 mw.msg() or mw.message() instead.
146 * mw.util.escapeId(), deprecated in 1.30, was removed. Use
147 mw.util.escapeIdForAttribute or mw.util.escapeIdForLink instead.
148 * mw.util.updateTooltipAccessKeys(), deprecated in 1.24, was removed. Use
149 jquery.accessKeyLabel instead.
150 * The SqlDataUpdate class, deprecated in 1.28, has been removed.
151 * The Html5Internal and Html5Depurate tidy driver classes were removed, along
152 with the Balancer tidy implementation. Both implementations were experimental,
153 and were replaced by RemexHtml.
154 * (T179624) Job::insert() and ::batchInsert(), deprecated in 1.21, were both
155 removed. Use JobQueueGroup::singleton()->push() instead.
156 * The jquery.footHovzer module, for mediawiki.debug, was removed.
157 * The es5-shim module, empty and deprecated since 1.29, was removed.
158 * the dom-level2-shim module, empty and deprecated since 1.29, was removed.
159 * the json module, empty and deprecated since 1.29, was removed.
160 * The mediawiki.widgets.visibleByteLimit module alias, deprecated in 1.32, was
161 removed. Use mediawiki.widgets.visibleLengthLimit instead.
162 * The jquery.farbtastic module, unused since 1.18, was removed.
163 * (T181318) The $wgStyleVersion setting and its appendage to various script and
164 style URLs in OutputPage, deprecated in 1.31, was removed.
165 * The hooks 'PreferencesFormPreSave' and 'PreferencesGetLegend' may provide
166 any HTMLForm object rather than PreferencesForm.
167 * The non namespaced TimestampException class, deprecated in 1.29, was removed.
168 Use Wikimedia\Timestamp\TimestampException instead.
169 * The global functions codepointToUtf8, hexSequenceToUtf8, utf8ToHexSequence,
170 utf8ToCodepoint, and escapeSingleString (deprecated in 1.25) were removed.
171 The UtfNormal\Utils class from the utfnormal library should be used instead.
172 * The deprecated UTF8_ and UNICODE_ constants were removed. The class constants
173 from the UtfNormal\Constants class from the utfnormal library should be used
174 * (T140807) The wgResourceLoaderLESSImportPaths configuration option was removed
175 from ResourceLoader. Instead, use `@import` statements in LESS to import
176 files directly from nearby directories within the same project.
177 * The protected methods PHPSessionHandler::returnSuccess() and returnFailure(),
178 only needed for PHP5 compatibility, have been removed. It now uses the boolean
179 values `true` and `false` respectively.
180 * The $parserMemc global and wfGetParserCacheStorage(), deprecated since 1.30,
181 were removed. Use the ParserCache class instead.
182 * ScopedCallback (deprecated in 1.28) was removed. Use Wikimedia\ScopedCallback
183 instead.
184 * Support for ResourceLoaderModule::getModifiedTime() and getModifiedHash(),
185 deprecated since 1.26, was removed. Use getDefinitionSummary() instead.
186 * (T195256) Skins are recommended not to rely on JavaScript for the "mw-jump"
187 and "jump-to-nav" accessibility links. To this end, the "jquery.mw-jump"
188 is no longer loaded by default. The Vector and MonoBook skins have made a
189 minor change to implement the toggle feature with CSS instead. To restore
190 prior functionality, either explicitly load "jquery.mw-jump" in your skin
191 or refer to T195256 for details on how to make the same change.
192 * Hook 'EditPageBeforeEditChecks' was removed;
193 use 'EditPageGetCheckboxesDefinition' instead.
194 * Linker::getLinkColour() and DummyLinker::getLinkColour(), deprecated since
195 1.28, were removed. LinkRenderer::getLinkClasses() should be used instead.
196 * Wikimedia\Rdbms\LoadBalancer::getLaggedSlaveMode(), deprecated in 1.28, has
197 been removed. Use Wikimedia\Rdbms\LoadBalancer::getLaggedReplicaMode()
198 instead.
199 * mw.widgets.CategoryMultiselectWidget now uses TagMultiselectWidget instead of
200 CapsuleMultiselectWidget. The following methods may no longer be used:
201 * setItemsFromData: Use setValue instead
202 * getItemsData: Use getItems instead and get the data property
203 * LanguageCode::bcp47() now always returns a valid BCP 47 code. This means
204 that some MediaWiki-specific language codes, such as `simple`, are mapped
205 into valid BCP 47 codes (eg `en-simple`).
206
207 === Deprecations in 1.32 ===
208 * Use of a StartProfiler.php file is deprecated in favour of placing
209 configuration in LocalSettings.php.
210 * HTMLForm::setSubmitProgressive() is deprecated. No need to call it. Submit
211 button is already marked as progressive.
212 * Skin::setupSkinUserCss() is deprecated. Adding of modules to load
213 has been centralised to Skin::getDefaultModules(), which is now capable
214 of queueing style modules as well.
215 * OutputPage::addModuleScripts() and ParserOutput::addModuleScripts are
216 deprecated. Use addModules() instead.
217 * Overriding SearchEngine::{searchText,searchTitle,searchArchiveTitle}
218 in extending classes is deprecated. Extend related doSearch* methods
219 instead.
220 * CollationFa has been removed completely as it's not needed anymore
221 * The following 'mediawiki.api' plugin modules were merged into mediawiki.api
222 and deprecated: mediawiki.api.category, mediawiki.api.edit,
223 mediawiki.api.login, mediawiki.api.options, mediawiki.api.parse,
224 mediawiki.api.upload, mediawiki.api.user, mediawiki.api.watch,
225 mediawiki.api.messages, and mediawiki.api.rollback.
226 * ApiBase::truncateArray() is deprecated. No replacement, as nothing is known
227 to use it.
228 * WatchAction::getUnwatchToken is deprecated. Use WatchAction::getWatchToken
229 with the 'unwatch' action parameter instead.
230 * IcuCollation::getICUVersion() is deprecated, as you can just use the PHP
231 constant INTL_ICU_VERSION directly in all versions that MediaWiki supports.
232 * Parser::fetchFile() is deprecated. Use ::fetchFileAndTitle() instead.
233 * The ApiQueryContributions class has been renamed to ApiQueryUserContribs.
234 * The XMPInfo, XMPReader, and XMPValidate classes have been deprecated in favor
235 of the namespaced classes provided by the wikimedia/xmp-reader library.
236 * SearchResultSet::{next,rewind} are deprecated. Calling code should
237 use foreach on the SearchResultSet, or the extractResults method. Extending
238 code should override extractResults.
239 * Instantiating SearchResultSet directly is deprecated. SearchEngine
240 implementations must subclass SearchResultSet for their purposes.
241 * SearchResult::setExtensionData argument has been changed from accepting an
242 array to accepting a Closure that returns the array when called.
243 * Class CryptRand, everything in MWCryptRand except generateHex() and function
244 MediaWikiServices::getCryptRand() are deprecated, use random_bytes() to
245 generate cryptographically secure random byte sequences.
246 * Parser::getConverterLanguage() is deprecated. Use ::getTargetLanguage()
247 instead.
248 * Language::markNoConversion() is deprecated. It confused readers because
249 it had unexpected behavior (only marking text if it looked like a URL)
250 and was only used in a single place in the code. Use
251 LanguageConverter::markNoConversion() instead.
252 * (T197492) Language::truncate() was soft deprecated in 1.31 and is
253 hard deprecated in this release. It has been split into two similar
254 methods, Language::truncateForVisual() and Language::truncateForDatabase(),
255 which measure length in characters and bytes, respectively. Use
256 Language::truncateForVisual() when possible to provide equity to users
257 of multibyte scripts.
258 * (T176526) EditPage::getContextTitle() falling back to $wgTitle when the
259 context title is unset is now deprecated; anything creating an EditPage
260 instance should set the context title via ::setContextTitle().
261 * The 'jquery.hidpi' module (polyfill for IMG srcset) is deprecated.
262 * ResourceLoaderStartUpModule::getStartupModules() and ::getLegacyModules()
263 are deprecated. These concepts are obsolete and have no replacement.
264 * String type for $lang of DifferenceEngine::setTextLanguage is deprecated.
265 * The following methods of OutputPage are now deprecated in favour
266 of using showFatalError directly: OutputPage::showFileDeleteError()
267 OutputPage::showFileNotFoundError(), OutputPage::showFileRenameError()
268 OutputPage::showFileCopyError() and OutputPage::showUnexpectedValueError().
269 * The Replacer, DoubleReplacer, HashtableReplacer, and RegexlikeReplacer
270 classes are now deprecated. Use a Closure instead.
271 * (T194263) ContentHandler::makeParserOptions() is deprecated. Use
272 WikiPage::makeParserOptions() or ParserOptions::newCanonical() instead.
273 * (T100681) Use of the Parsoid v1 API with the VirtualRESTService, deprecated in
274 MediaWiki 1.26, is now hard-deprecated. All known clients were converted to
275 the Parsoid v3 API in May 2015.
276 * $input is deprecated in hook 'LogEventsListGetExtraInputs'. Use
277 $formDescriptor instead.
278 * SearchEngine::transformSearchTerm( $term ) should no longer be called prior
279 to running searchText. This method was mainly implemented to support the
280 'prefix' URI param in SpecialSearch, but there are no reasons to expose this
281 logic as it should be handled internally by SearchEngine implementations
282 supporting this feature. SearchEngine implementations should no longer
283 override this methods.
284 * SearchEngine::replacePrefixes( $query ) should no longer be called prior
285 to running searchText/searchTitle.
286 * (T199657) Messages for $wgFilterLogTypes labels should be no longer be in the
287 'log-show-hide-[type]' format. Instead use 'logeventslist-[type]-log'.
288 * Global functions wfArrayFilter() and wfArrayFilterByKey() are deprecated.
289 use array_filter() directly.
290
291 === Other changes in 1.32 ===
292 * (T198811) The following tables have had their UNIQUE indexes turned into
293 proper PRIMARY KEYs for increased maintainability: interwiki, page_props,
294 protected_titles and site_identifiers.
295 * …
296
297 == Compatibility ==
298 MediaWiki 1.32 requires PHP 7.0.0 or later. Although HHVM 3.18.5 or later is
299 supported, it is generally advised to use PHP 7.0.0 or later for long term
300 support.
301
302 MySQL/MariaDB is the recommended DBMS. PostgreSQL or SQLite can also be used,
303 but support for them is somewhat less mature. There is experimental support for
304 Oracle and Microsoft SQL Server.
305
306 The supported versions are:
307
308 * MySQL 5.5.8 or later
309 * PostgreSQL 9.2 or later
310 * SQLite 3.3.7 or later
311 * Oracle 9.0.1 or later
312 * Microsoft SQL Server 2005 (9.00.1399)
313
314 == Upgrading ==
315 1.32 has several database changes since 1.31, and will not work without schema
316 updates. Note that due to changes to some very large tables like the revision
317 table, the schema update may take quite long (minutes on a medium sized site,
318 many hours on a large site).
319
320 Don't forget to always back up your database before upgrading!
321
322 See the file UPGRADE for more detailed upgrade instructions, including
323 important information when upgrading from versions prior to 1.11.
324
325 For notes on 1.31.x and older releases, see HISTORY.
326
327 == Online documentation ==
328 Documentation for both end-users and site administrators is available on
329 MediaWiki.org, and is covered under the GNU Free Documentation License (except
330 for pages that explicitly state that their contents are in the public domain):
331
332 https://www.mediawiki.org/wiki/Special:MyLanguage/Documentation
333
334 == Mailing list ==
335 A mailing list is available for MediaWiki user support and discussion:
336
337 https://lists.wikimedia.org/mailman/listinfo/mediawiki-l
338
339 A low-traffic announcements-only list is also available:
340
341 https://lists.wikimedia.org/mailman/listinfo/mediawiki-announce
342
343 It's highly recommended that you sign up for one of these lists if you're
344 going to run a public MediaWiki, so you can be notified of security fixes.
345
346 == IRC help ==
347 There's usually someone online in #mediawiki on irc.freenode.net.