Add getLoginSecurityLevel() support to FormSpecialPage
[lhc/web/wiklou.git] / RELEASE-NOTES-1.32
1 == MediaWiki 1.32 ==
2
3 THIS IS NOT A RELEASE YET
4
5 MediaWiki 1.32 is an alpha-quality branch and is not recommended for use in
6 production.
7
8 === Configuration changes in 1.32 ===
9 * (T115414) The $wgEnableAPI and $wgEnableWriteAPI settings, deprecated in 1.31,
10 have been removed.
11 * The $wgUseAjax setting, deprecated in 1.31, is now ignored.
12 * The $wgSiteSupportPage setting, unused since 1.5, was removed.
13 * The default quality of JPEG thumbnails generated by GD was reduced from 95 to
14 80. The quality of JPEG thumbnails is now configurable through the new setting
15 $wgJpegQuality (default 80). This aligns the quality to what ImageMagick uses.
16 * $wgExperimentalHtmlIds, deprecated since 1.30, has been removed. The
17 'html5-legacy' value for $wgFragmentMode is no longer accepted.
18 * The experimental Html5Internal and Html5Depurate tidy drivers were removed.
19 RemexHtml, which is the default, should be used instead.
20 * (T135963) You can now define a Content Security Policy for your wiki. This
21 adds a defense-in-depth feature to stop an attacker who has found a bug in
22 the parser allowing them to insert malicious attributes. Disabled by default,
23 you can configure this via $wgCSPHeader and $wgCSPReportOnlyHeader.
24 * New configuration variable has been added: $wgCookieSetOnIpBlock.
25 This determines whether to set a cookie when an IP user is blocked. Doing so means
26 that a blocked user, even after moving to a new IP address, will still be blocked.
27 * The archive table's ar_rev_id field is now unique.
28
29 === New features in 1.32 ===
30 * (T112474) Generalized the ResourceLoader mechanism for overriding modules
31 using a particular page during edit previews.
32 * (T12331) You can now log page creation events by setting $wgPageCreationLog
33 to true.
34 * Added 'ApiParseMakeOutputPage' hook.
35 * (T174313) Added checkbox on Special:ListUsers to display only users in
36 temporary user groups.
37 * (T152462) A cookie can now be set when an IP user is blocked to track that user if
38 they move to a new IP address. This is disabled by default.
39 * (T194950) Added 'ApiMaxLagInfo' hook.
40 * SpecialPage::checkLoginSecurityLevel() will now preserve POST data when
41 reauthenticating.
42 * FormSpecialPage::execute() will now call checkLoginSecurityLevel() if
43 getLoginSecurityLevel() returns non-false.
44
45 === External library changes in 1.32 ===
46 * …
47
48 ==== Upgraded external libraries ====
49 * Updated QUnit from 2.4.0 to 2.6.0.
50 * Updated wikimedia/scoped-callback from 1.0.0 to 2.0.0.
51 ** ScopedCallback objects can no longer be serialized.
52
53 ==== New external libraries ====
54 * Added wikimedia/xmp-reader 0.5.1
55 * …
56
57 ==== Removed and replaced external libraries ====
58 * …
59
60 === Bug fixes in 1.32 ===
61 * SpecialPage::execute() will now only call checkLoginSecurityLevel() if
62 getLoginSecurityLevel() returns non-false.
63
64 === Action API changes in 1.32 ===
65 * Added templated parameters.
66 * A module can define a templated parameter like "{fruit}-quantity", where
67 the actual parameters recognized correspond to the values of a multi-valued
68 parameter. Then clients can make requests like
69 "fruits=apples|bananas&apples-quantity=1&bananas-quantity=5".
70 * action=paraminfo will return templated parameter definitions separately
71 from normal parameters. All parameter definitions now include an "index"
72 key to allow clients to maintain parameter ordering when merging normal and
73 templated parameters.
74 * It is now an error to submit too many values for a multi-valued parameter.
75 This has generated a warning since MediaWiki 1.14.
76
77 === Action API internal changes in 1.32 ===
78 * Added 'ApiParseMakeOutputPage' hook.
79 * Parameter names may no longer contain '{' or '}', as these are now used for
80 templated parameters.
81 * (T194950) Added 'ApiMaxLagInfo' hook.
82
83 === Languages updated in 1.32 ===
84 MediaWiki supports over 350 languages. Many localisations are updated regularly.
85 Below only new and removed languages are listed, as well as changes to languages
86 because of Phabricator reports.
87
88 * (T193566) Added language support for Ambonese Malay (abs).
89 * (T194047) Added language support for Shawiya, Latin script (shy-latn).
90 * (T195940) Added language support for Batak Mandailing (btm).
91
92 === Breaking changes in 1.32 ===
93 * $wgRequestTime, deprecated in 1.25, was removed. Use
94 $_SERVER['REQUEST_TIME_FLOAT'] or WebRequest::getElapsedTime() instead.
95 * The MediaWikiI18N class, deprecated in 1.31, was removed.
96 * QuickTemplate::setTranslator(), deprecated in 1.31, was removed. Use
97 Skin::msg() instead.
98 * wfInitShellLocale(), deprecated in 1.30, was removed.
99 * wfShellExecDisabled(), deprecated in 1.30, was removed.
100 * The type string for the parameter $lang of DateFormatter::getInstance,
101 deprecated in 1.31, was removed.
102 * The EDIT_TOKEN_SUFFIX constant deprecated in 1.27, was removed. Use
103 MediaWiki\Session\Token::SUFFIX instead.
104 * EditPage::isOouiEnabled() deprecated in 1.30, was removed.
105 * mw.util.wikiGetlink(), deprecated in 1.23, was removed. Use mw.util.getUrl()
106 instead.
107 * (T61113) The following methods and constants from the Revision class, which
108 were deprecated in 1.25, have now been removed:
109 * Revision::getRawUser()
110 * Revision::getRawUserText()
111 * Revision::getRawComment()
112 * window.gM() from mediawiki.jqueryMsg, deprecated in 1.23, was removed. Use
113 mw.msg() or mw.message() instead.
114 * mw.util.escapeId(), deprecated in 1.30, was removed. Use
115 mw.util.escapeIdForAttribute or mw.util.escapeIdForLink instead.
116 * mw.util.updateTooltipAccessKeys(), deprecated in 1.24, was removed. Use
117 jquery.accessKeyLabel instead.
118 * The SqlDataUpdate class, deprecated in 1.28, has been removed.
119 * The Html5Internal and Html5Depurate tidy driver classes were removed, along
120 with the Balancer tidy implementation. Both implementations were experimental,
121 and were replaced by RemexHtml.
122 * (T179624) Job::insert() and ::batchInsert(), deprecated in 1.21, were both
123 removed. Use JobQueueGroup::singleton()->push() instead.
124 * The jquery.footHovzer module, for mediawiki.debug, was removed.
125 * The es5-shim module, empty and deprecated since 1.29, was removed.
126 * The mediawiki.widgets.visibleByteLimit module alias, deprecated in 1.32, was
127 removed. Use mediawiki.widgets.visibleLengthLimit instead.
128 * The jquery.farbtastic module, unused since 1.18, was removed.
129 * (T181318) The $wgStyleVersion setting and its appendage to various script and
130 style URLs in OutputPage, deprecated in 1.31, was removed.
131 * The hooks 'PreferencesFormPreSave' and 'PreferencesGetLegend' may provide
132 any HTMLForm object rather than PreferencesForm.
133 * The non namespaced TimestampException class, deprecated in 1.29, was removed.
134 Use Wikimedia\Timestamp\TimestampException instead.
135 * The global functions codepointToUtf8, hexSequenceToUtf8, utf8ToHexSequence,
136 utf8ToCodepoint, and escapeSingleString (deprecated in 1.25) were removed.
137 The UtfNormal\Utils class from the utfnormal library should be used instead.
138 * The deprecated UTF8_ and UNICODE_ constants were removed. The class constants
139 from the UtfNormal\Constants class from the utfnormal library should be used
140 * (T140807) The wgResourceLoaderLESSImportPaths configuration option was removed
141 from ResourceLoader. Instead, use `@import` statements in LESS to import
142 files directly from nearby directories within the same project.
143 * The protected methods PHPSessionHandler::returnSuccess() and returnFailure(),
144 only needed for PHP5 compatibility, have been removed. It now uses the boolean
145 values `true` and `false` respectively.
146 * The $parserMemc global and wfGetParserCacheStorage(), deprecated since 1.30,
147 were removed. Use the ParserCache class instead.
148 * ScopedCallback (deprecated in 1.28) was removed. Use Wikimedia\ScopedCallback
149 instead.
150 * Support for ResourceLoaderModule::getModifiedTime() and getModifiedHash(),
151 deprecated since 1.26, was removed. Use getDefinitionSummary() instead.
152
153 === Deprecations in 1.32 ===
154 * Use of a StartProfiler.php file is deprecated in favour of placing
155 configuration in LocalSettings.php.
156 * HTMLForm::setSubmitProgressive() is deprecated. No need to call it. Submit
157 button is already marked as progressive.
158 * Skin::setupSkinUserCss() is deprecated. Adding of modules to load
159 has been centralised to Skin::getDefaultModules(), which is now capable
160 of queueing style modules as well.
161 * OutputPage::addModuleScripts() and ParserOutput::addModuleScripts are
162 deprecated. Use addModules() instead.
163 * Overriding SearchEngine::{searchText,searchTitle,searchArchiveTitle}
164 in extending classes is deprecated. Extend related doSearch* methods
165 instead.
166 * CollationFa has been removed completely as it's not needed anymore
167 * The following 'mediawiki.api' plugin modules were merged into mediawiki.api
168 and deprecated: mediawiki.api.category, mediawiki.api.edit,
169 mediawiki.api.login, mediawiki.api.options, mediawiki.api.parse,
170 mediawiki.api.upload, mediawiki.api.user, mediawiki.api.watch,
171 mediawiki.api.messages, and mediawiki.api.rollback.
172 * ApiBase::truncateArray() is deprecated. No replacement, as nothing is known
173 to use it.
174 * WatchAction::getUnwatchToken is deprecated. Use WatchAction::getWatchToken
175 with the 'unwatch' action parameter instead.
176 * IcuCollation::getICUVersion() is deprecated, as you can just use the PHP
177 constant INTL_ICU_VERSION directly in all versions that MediaWiki supports.
178 * Parser::fetchFile() is deprecated. Use ::fetchFileAndTitle() instead.
179 * The ApiQueryContributions class has been renamed to ApiQueryUserContribs.
180 * The XMPInfo, XMPReader, and XMPValidate classes have been deprecated in favor
181 of the namespaced classes provided by the wikimedia/xmp-reader library.
182
183 === Other changes in 1.32 ===
184 * …
185
186 == Compatibility ==
187 MediaWiki 1.32 requires PHP 7.0.0 or later. Although HHVM 3.18.5 or later is
188 supported, it is generally advised to use PHP 7.0.0 or later for long term
189 support.
190
191 MySQL/MariaDB is the recommended DBMS. PostgreSQL or SQLite can also be used,
192 but support for them is somewhat less mature. There is experimental support for
193 Oracle and Microsoft SQL Server.
194
195 The supported versions are:
196
197 * MySQL 5.5.8 or later
198 * PostgreSQL 9.2 or later
199 * SQLite 3.3.7 or later
200 * Oracle 9.0.1 or later
201 * Microsoft SQL Server 2005 (9.00.1399)
202
203 == Upgrading ==
204 1.32 has several database changes since 1.31, and will not work without schema
205 updates. Note that due to changes to some very large tables like the revision
206 table, the schema update may take quite long (minutes on a medium sized site,
207 many hours on a large site).
208
209 Don't forget to always back up your database before upgrading!
210
211 See the file UPGRADE for more detailed upgrade instructions, including
212 important information when upgrading from versions prior to 1.11.
213
214 For notes on 1.31.x and older releases, see HISTORY.
215
216 == Online documentation ==
217 Documentation for both end-users and site administrators is available on
218 MediaWiki.org, and is covered under the GNU Free Documentation License (except
219 for pages that explicitly state that their contents are in the public domain):
220
221 https://www.mediawiki.org/wiki/Special:MyLanguage/Documentation
222
223 == Mailing list ==
224 A mailing list is available for MediaWiki user support and discussion:
225
226 https://lists.wikimedia.org/mailman/listinfo/mediawiki-l
227
228 A low-traffic announcements-only list is also available:
229
230 https://lists.wikimedia.org/mailman/listinfo/mediawiki-announce
231
232 It's highly recommended that you sign up for one of these lists if you're
233 going to run a public MediaWiki, so you can be notified of security fixes.
234
235 == IRC help ==
236 There's usually someone online in #mediawiki on irc.freenode.net.