API: Add authz features for RESTBase
[lhc/web/wiklou.git] / RELEASE-NOTES-1.25
1 Security reminder: If you have PHP's register_globals option set, you must
2 turn it off. MediaWiki will not work with it enabled.
3
4 == MediaWiki 1.25 ==
5
6 THIS IS NOT A RELEASE YET
7
8 MediaWiki 1.25 is an alpha-quality branch and is not recommended for use in
9 production.
10
11 === Configuration changes in 1.25 ===
12 * $wgPageShowWatchingUsers was removed.
13 * $wgLocalVirtualHosts has been added to replace $wgConf->localVHosts.
14 * $wgAntiLockFlags was removed.
15 * $wgJavaScriptTestConfig was removed.
16 * Edit tokens returned from User::getEditToken may change on every call. Token
17 validity must be checked by passing the user-supplied token to
18 User::matchEditToken rather than by testing for equality with a
19 newly-generated token.
20 * (T74951) The UserGetLanguageObject hook may be passed any IContextSource
21 for its $context parameter. Formerly it was documented as receiving a
22 RequestContext specifically.
23 * Profiling was restructured and $wgProfiler now requires an 'output' parameter.
24 See StartProfiler.sample for details.
25 * $wgMangleFlashPolicy was added to make MediaWiki's mangling of anything that
26 might be a flash policy directive configurable.
27 * ApiOpenSearch now supports XML output. The OpenSearchXml extension should no
28 longer be used. If extracts and page images are desired, the TextExtracts and
29 PageImages extensions are required.
30 * $wgOpenSearchTemplate is deprecated in favor of $wgOpenSearchTemplates.
31 * Edits are now prepared via AJAX as users type edit summaries. This behavior
32 can be disabled via $wgAjaxEditStash.
33 * (T46740) The temporary option $wgIncludejQueryMigrate was removed, along
34 with the jQuery Migrate library, as indicated when this option was provided in
35 MediaWiki 1.24.
36 * ProfilerStandard and ProfilerSimpleTrace were removed. Make sure that any
37 StartProfiler.php config is updated to reflect this. Xhprof is available
38 for zend/hhvm. Also, for hhvm, one can consider using its xenon profiler.
39 * Default value of $wgSVGConverters['rsvg'] now uses the 'rsvg-convert' binary
40 rather than 'rsvg'.
41 * Default value of $wgSVGConverters['ImageMagick'] now uses transparent
42 background with white fallback color, rather than just white background.
43 * MediaWikiBagOStuff class removed, make sure any object cache config
44 uses SqlBagOStuff instead.
45 * The 'daemonized' flag must be set to true in $wgJobTypeConf for any redis
46 job queues. This means that mediawiki/services/jobrunner service has to
47 be installed and running for any such queues to work.
48
49 === New features in 1.25 ===
50 * (T64861) Updated plural rules to CLDR 26. Includes incompatible changes
51 for plural forms in Russian, Prussian, Tagalog, Manx and several languages
52 that fall back to Russian.
53 * (T60139) ResourceLoaderFileModule now supports language fallback
54 for 'languageScripts'.
55 * Added a new hook, "ContentAlterParserOutput", to allow extensions to modify the
56 parser output for a content object before links update.
57 * (T37785) Enhanced recent changes and extended watchlist are now default.
58 Documentation: https://meta.wikimedia.org/wiki/Help:Enhanced_recent_changes
59 and https://www.mediawiki.org/wiki/Manual:$wgDefaultUserOptions.
60 * (T69341) SVG images will no longer be base64-encoded when being embedded
61 in CSS. This results in slight size increase before gzip compression (due to
62 percent-encoding), but up to 20% decrease after it.
63 * Update jStorage to v0.4.12.
64 * MediaWiki now natively supports page status indicators: icons (or short text
65 snippets) usually displayed in the top-right corner of the page. They have
66 been in use on Wikipedia for a long time, implemented using templates and CSS
67 absolute positioning.
68 - Basic wikitext syntax: <indicator name="foo">[[File:Foo.svg|20px]]</indicator>
69 - Usage instructions: https://www.mediawiki.org/wiki/Help:Page_status_indicators
70 - Adjusting custom skins to support indicators:
71 https://www.mediawiki.org/wiki/Manual:Skinning#Page_status_indicators
72 * Edit tokens may now be time-limited: passing a maximum age to
73 User::matchEditToken will reject any older tokens.
74 * The debug logging internals have been overhauled, and are now using the
75 PSR-3 interfaces.
76 * Update CSSJanus to v1.1.1.
77 * Update lessphp to v0.5.0.
78 * Added a hook, "ApiOpenSearchSuggest", to allow extensions to provide extracts
79 and images for ApiOpenSearch output. The semantics are identical to the
80 "OpenSearchXml" hook provided by the OpenSearchXml extension.
81 * PrefixSearchBackend hook now has an $offset parameter. Combined with $limit,
82 this allows for pagination of prefix results. Extensions using this hook
83 should implement supporting behavior. Not doing so can result in undefined
84 behavior from API clients trying to continue through prefix results.
85 * Update jQuery from v1.11.1 to v1.11.2.
86 * External libraries installed via composer will now be displayed
87 on Special:Version in their own section. Extensions or skins that are
88 installed via composer will not be shown in this section as it is assumed
89 they will add the proper credits to the skins or extensions section. They
90 can also be accessed through the API via the new siprop=libraries to
91 ApiQuerySiteInfo.
92 * Update QUnit from v1.14.0 to v1.16.0.
93 * Update Moment.js from v2.8.3 to v2.8.4.
94 * Special:Tags now allows for manipulating the list of user-modifiable change
95 tags. Actually modifying the tagging of a revision or log entry is not
96 implemented yet.
97 * Added 'managetags' user right and 'ChangeTagCanCreate', 'ChangeTagCanDelete',
98 and 'ChangeTagCanCreate' hooks to allow for managing user-modifiable change
99 tags.
100 * Added 'ChangeTagsListActive' hook, to separate the concepts of "defined" and
101 "active" formerly conflated by the 'ListDefinedTags' hook.
102
103 ==== External libraries ====
104 * MediaWiki now requires certain external libraries to be installed. In the past
105 these were bundled inside the Git repository of MediaWiki core, but now they
106 need to be installed separately. For users using the tarball, this will be taken
107 care of and no action will be required. Users using Git will either need to use
108 composer to fetch dependencies or use the mediawiki/vendor repository which includes
109 all dependencies for MediaWiki core and ones used in Wikimedia deployment. Detailed
110 instructions can be found at:
111 https://www.mediawiki.org/wiki/Download_from_Git#Fetch_external_libraries
112 * The following libraries are now required:
113 ** psr/log
114 This library provides the interfaces set by the PSR-3 standard (http://www.php-fig.org/psr/psr-3/)
115 which are used by MediaWiki internally via the MWLoggerFactory class.
116 See the structured logging RfC (https://www.mediawiki.org/wiki/Requests_for_comment/Structured_logging)
117 for more background information.
118 ** cssjanus/cssjanus
119 This library was formerly bundled with MediaWiki core and has been removed.
120 It automatically flips CSS for RTL support.
121 ** leafo/lessphp
122 This library was formerly bundled with MediaWiki core and has been removed.
123 It compiles LESS files into CSS.
124 ** wikimedia/cdb
125 This library was formerly a part of MediaWiki core, and has been moved into a separate library.
126 It provides CDB functions which are used in the Interwiki and Localization caches.
127 More information about the library can be found at https://www.mediawiki.org/wiki/CDB.
128
129 === Bug fixes in 1.25 ===
130 * (T73003) No additional code will be generated to try to load CSS-embedded
131 SVG images in Internet Explorer 6 and 7, as they don't support them anyway.
132 * (T69021) On Special:BookSources, corrected validation of ISBNs (both
133 10- and 13-digit forms) containing "X".
134 * Page moving was refactored into a MovePage class. As part of that:
135 ** The AbortMove hook was removed.
136 ** MovePageIsValidMove is for extensions to specify whether a page
137 cannot be moved for technical reasons, and should not be overridden.
138 ** MovePageCheckPermissions is for checking whether the given user is
139 allowed to make the move.
140 ** Title::moveNoAuth() was deprecated. Use the MovePage class instead.
141 ** Title::moveTo() was deprecated. Use the MovePage class instead.
142 ** Title::isValidMoveOperation() broken down into MovePage::isValidMove()
143 and MovePage::checkPermissions().
144 * (T18530) Multiple autocomments are now formatted in an edit summary.
145 * (T70361) Autocomments containing "/*" are parsed correctly.
146 * The Special:WhatLinksHere page linked from 'Number of redirects to this page'
147 on action=info about a file page does not list file links anymore.
148 * (T78637) Search bar is not autofocused unless it is empty so that proper scrolling using arrow keys is possible.
149 * (T50853) Database::makeList() modified to handle 'NULL' separately when building IN clause
150 * (T85192) Captcha position modified in Usercreate template. As a result:
151 ** extrafields parameter added to Usercreate.php to insert additional data
152 ** 'extend' method added to QuickTemplate to append additional values to any field of data array
153 * (T86974) Several Title methods now load from the database when necessary
154 (instead of returning incorrect results) even when the page ID is known.
155 * (T74070) Duplicate search for archived files on file upload now omits the extension.
156 This requires the fa_sha1 field being populated.
157
158 === Action API changes in 1.25 ===
159 * (T67403) XML tag highlighting is now only performed for formats
160 "xmlfm" and "wddxfm".
161 * action=paraminfo supports generalized submodules (modules=query+value),
162 querymodules and formatmodules are deprecated
163 * action=paraminfo no longer outputs descriptions and other help text by
164 default. If needed, it may be requested using the new 'helpformat' parameter.
165 * action=help has been completely rewritten, and outputs help in HTML
166 rather than plain text.
167 * Hitting api.php without specifying an action now displays only the help for
168 the main module, with links to submodule help.
169 * API help is no longer displayed on errors.
170 * 'uselang' is now a recognized API parameter; "uselang=user" may be used to
171 explicitly select the language from the current user's preferences, and
172 "uselang=content" may be used to select the wiki's content language.
173 * Default output format for the API is now jsonfm.
174 * Simplified continuation will return a "batchcomplete" property in the result
175 when a batch of pages is complete.
176 * Pretty-printed HTML output now has nicer formatting and (if available)
177 better syntax highlighting.
178 * Deprecated list=deletedrevs in favor of newly-added prop=deletedrevisions and
179 list=alldeletedrevisions.
180 * prop=revisions will gracefully continue when given too many revids or titles,
181 rather than just ignoring the extras.
182 * prop=revisions will no longer die if rvcontentformat doesn't match a
183 revision's content model; it will instead warn and omit the content.
184 * If the user has the 'deletedhistory' right, action=query's revids parameter
185 will now recognize deleted revids.
186 * prop=revisions may be used as a generator, generating revids.
187 * (T68776) format=json results will no longer be corrupted when
188 $wgMangleFlashPolicy is in effect. format=php results will cleanly return an
189 error instead of returning invalid serialized data.
190 * Generators may now return data for the generated pages when used with
191 action=query.
192 * Query page data for generator=search and generator=prefixsearch will now
193 include an "index" field, which may be used by the client for sorting the
194 search results.
195 * ApiOpenSearch now supports XML output.
196 * ApiOpenSearch will now output descriptions and URLs as array indexes 2 and 3
197 in JSON format.
198 * (T76051) list=tags will now continue correctly.
199 * (T76052) list=tags can now indicate whether a tag is defined.
200 * (T75522) list=prefixsearch now supports continuation
201 * (T78737) action=expandtemplates can now return page properties.
202 * (T78690) list=allimages now accepts multiple pipe-separated values
203 for the 'aimime' parameter.
204 * prop=info with inprop=protections will now return applicable protection types
205 with the 'restrictiontypes' key.
206 * (T85417) When resolving redirects, ApiPageSet will now add the targets of
207 interwiki redirects to the list of interwiki titles.
208 * (T85417) When outputting the list of redirect titles, a 'tointerwiki'
209 property (like the existing 'tofragment' property) will be set.
210 * Added action=managetags to allow for managing the list of
211 user-modifiable change tags. Actually modifying the tagging of a revision or
212 log entry is not implemented yet.
213 * list=tags has additional properties to indicate 'active' status and tag
214 sources.
215 * siprop=libraries was added to ApiQuerySiteInfo to list installed external libraries.
216 * (T88010) Added action=checktoken, to test a CSRF token's validity.
217 * (T88010) Added intestactions to prop=info, to allow querying of
218 Title::userCan() via the API.
219
220 === Action API internal changes in 1.25 ===
221 * ApiHelp has been rewritten to support i18n and paginated HTML output.
222 Most existing modules should continue working without changes, but should do
223 the following:
224 * Add an i18n message "apihelp-{$moduleName}-description" to replace getDescription().
225 * Add i18n messages "apihelp-{$moduleName}-param-{$param}" for each parameter
226 to replace getParamDescription(). If necessary, the settings array returned
227 by getParams() can use the new ApiBase::PARAM_HELP_MSG key to override the
228 message.
229 * Implement getExamplesMessages() to replace getExamples().
230 * Modules with submodules (like action=query) must have their submodules
231 override ApiBase::getParent() to return the correct parent object.
232 * The 'APIGetDescription' and 'APIGetParamDescription' hooks are deprecated,
233 and will have no effect for modules using i18n messages. Use
234 'APIGetDescriptionMessages' and 'APIGetParamDescriptionMessages' instead.
235 * Api formatters will no longer be asked to display the help screen on errors.
236 * ApiMain::getCredits() was removed. The credits are available in the
237 'api-credits' i18n message.
238 * ApiFormatBase has been changed to support i18n and syntax highlighting via
239 extensions with the new 'ApiFormatHighlight' hook. Core syntax highlighting
240 has been removed.
241 * ApiFormatBase now always buffers. Output is done when
242 ApiFormatBase::closePrinter is called.
243 * Much of the logic in ApiQueryRevisions has been split into ApiQueryRevisionsBase.
244 * The 'revids' parameter supplied by ApiPageSet will now count deleted
245 revisions as "good" if the user has the 'deletedhistory' right. New methods
246 ApiPageSet::getLiveRevisionIDs() and ApiPageSet::getDeletedRevisionIDs() are
247 provided to access just the live or just the deleted revids.
248 * Added ApiPageSet::setGeneratorData() and ApiPageSet::populateGeneratorData()
249 to allow generators to include data in the action=query result.
250 * The following methods have been deprecated and may be removed in a future
251 release:
252 * ApiBase::getDescription
253 * ApiBase::getParamDescription
254 * ApiBase::getExamples
255 * ApiBase::makeHelpMsg
256 * ApiBase::makeHelpArrayToString
257 * ApiBase::makeHelpMsgParameters
258 * ApiFormatBase::setUnescapeAmps
259 * ApiFormatBase::getWantsHelp
260 * ApiFormatBase::setHelp
261 * ApiFormatBase::formatHTML
262 * ApiFormatBase::setBufferResult
263 * ApiFormatBase::getDescription
264 * ApiMain::setHelp
265 * ApiMain::reallyMakeHelpMsg
266 * ApiMain::makeHelpMsgHeader
267 * ApiQueryImageInfo::getPropertyDescriptions
268 * The following classes have been deprecated and may be removed in a future
269 release:
270 * ApiQueryDeletedrevs
271
272 === Languages updated in 1.25 ===
273
274 MediaWiki supports over 350 languages. Many localisations are updated
275 regularly. Below only new and removed languages are listed, as well as
276 changes to languages because of Bugzilla reports.
277
278 * (T66440) Kazakh (kk) wikis should no longer forcefully reset the user's
279 interface language to kk where unexpected.
280
281 === Other changes in 1.25 ===
282 * The skin autodiscovery mechanism, deprecated in MediaWiki 1.23, has been
283 removed. See https://www.mediawiki.org/wiki/Manual:Skin_autodiscovery for
284 migration guide for creators and users of custom skins that relied on it.
285 * Javascript variables 'wgFileCanRotate' and 'wgFileExtensions' now only
286 available on Special:Upload.
287 * (T58257) Set site logo from mediawiki.skinning.interface module instead of
288 inline styles in the HTML.
289 * Removed ApiQueryUsers::getAutoGroups(). (deprecated since 1.20)
290 * Removed XmlDumpWriter::schemaVersion(). (deprecated since 1.20)
291 * Removed LogEventsList::getDisplayTitle(). (deprecated since 1.20)
292 * Removed Preferences::trySetUserEmail(). (deprecated since 1.20)
293 * Removed mw.user.name() and mw.user.anonymous() methods. (deprecated since 1.20)
294 * Removed 'ok' and 'err' parameters in the mediawiki.api modules. (deprecated
295 since 1.20)
296 * Removed 'async' parameter from the mw.Api#getCategories() method. (deprecated
297 since 1.20)
298 * Removed 'jquery.json' module. (deprecated since 1.24)
299 Use the 'json' module and global JSON object instead.
300 * Deprecated OutputPage::readOnlyPage() and OutputPage::rateLimited().
301 Also, the former will now throw an MWException if called with one or more
302 arguments.
303 * Removed hitcounters and associated code.
304 * The "temp" zone of the upload respository is now considered private. If it
305 already exists (such as under the images/ directory), please make sure that
306 the directory is not web readable (e.g. via a .htaccess file).
307 * BREAKING CHANGE: In the XML dump format used by Special:Export and
308 dumpBackup.php, the <model> and <format> tags now apprear before the <text>
309 tag, instead of after the <text> and <sha1> tags.
310 The new schema version is 0.10, the new schema URI is:
311 https://www.mediawiki.org/xml/export-0.10.xsd
312 * MWFunction::call() and MWFunction::callArray() were removed, having being
313 deprecated in 1.22.
314 * Deprecated the getInternalLinkAttributes, getInternalLinkAttributesObj,
315 and getInternalLinkAttributes methods in Linker, and removed
316 getExternalLinkAttributes method, which was deprecated in MediaWiki 1.18.
317 * Removed Sites class, which was deprecated in 1.21 and replaced by SiteSQLStore.
318 * The mw.api.getToken() method now uses action=query?meta=tokens. This will now
319 fail for custom tokens registered only via the deprecated ApiTokensGetTokenTypes
320 hook. The ApiQueryTokensRegisterTypes hook should be used for this to work.
321 * Added wgRelevantArticleId to the client-side config, for use on special pages.
322 * Deprecated the TitleIsCssOrJsPage hook. Superseded by the
323 ContentHandlerDefaultModelFor hook since MediaWiki 1.21.
324 * Deprecated the TitleIsWikitextPage hook. Superseded by the
325 ContentHandlerDefaultModelFor hook since MediaWiki 1.21.
326 * Changed parsing of variables in schema (.sql) files:
327 ** The substituted values are no longer parsed. (Formerly, several passes
328 were made for each variable, so depending on the order in which variables
329 were defined, variables might have been found inside encoded values. This
330 is no longer the case.)
331 ** Variables are no longer string encoded when the /*$var*/ syntax is used.
332 If string encoding is necessary, use the '{$var}' syntax instead.
333 ** Variable names must only consist of one or more of the characters
334 "A-Za-z0-9_".
335 ** In source text of the form '{$A}'{$B}' or `{$A}`{$B}`, where variable A
336 does not exist yet variable B does, the latter may not be replaced.
337 However, this difference is unlikely to arise in practice.
338 * (T67278) RFC, PMID, and ISBN "magic links" must be surrounded by non-word
339 characters on both sides.
340 * The FormatAutocomments hook will now receive $pre and $post as booleans,
341 rather than as strings that must be prepended or appended to $comment.
342 * (T30950, T31025) RFC, PMID, and ISBN "magic links" can no longer contain
343 newlines; but they can contain &nbsp; and other non-newline whitespace.
344 * The 'mediawiki.action.edit' ResourceLoader module no longer generates the edit
345 toolbar, which has been moved to a separate 'mediawiki.toolbar' module. If you
346 relied on this behavior, update your scripts' dependencies.
347 * HTMLForm's 'vform' display style has been separated to a subclass. Therefore:
348 * HTMLForm::isVForm() is now deprecated.
349 * You can no longer do this:
350 $form = new HTMLForm( … );
351 $form->setDisplayFormat( 'vform' ); // throws exception
352 Instead, do this:
353 $form = HTMLForm::factory( 'vform', … );
354 * Deprecated Revision methods getRawUser(), getRawUserText() and getRawComment().
355 * BREAKING CHANGE: mediawiki.user.generateRandomSessionId:
356 The alphabet of the prior string returned was A-Za-z0-9 and now it is 0-9A-F
357 * (T87504) Avoid serving SVG background-images in CSS for Opera 12, which
358 renders them incorrectly when combined with border-radius or background-size.
359
360 == Compatibility ==
361
362 MediaWiki 1.25 requires PHP 5.3.3 or later. There is experimental support for
363 HHVM 3.3.0.
364
365 MySQL is the recommended DBMS. PostgreSQL or SQLite can also be used, but
366 support for them is somewhat less mature. There is experimental support for
367 Oracle and Microsoft SQL Server.
368
369 The supported versions are:
370
371 * MySQL 5.0.2 or later
372 * PostgreSQL 8.3 or later
373 * SQLite 3.3.7 or later
374 * Oracle 9.0.1 or later
375 * Microsoft SQL Server 2005 (9.00.1399)
376
377 == Upgrading ==
378
379 1.25 has several database changes since 1.24, and will not work without schema
380 updates. Note that due to changes to some very large tables like the revision
381 table, the schema update may take quite long (minutes on a medium sized site,
382 many hours on a large site).
383
384 If upgrading from before 1.11, and you are using a wiki as a commons
385 repository, make sure that it is updated as well. Otherwise, errors may arise
386 due to database schema changes.
387
388 If upgrading from before 1.7, you may want to run refreshLinks.php to ensure
389 new database fields are filled with data.
390
391 If you are upgrading from MediaWiki 1.4.x or earlier, you should upgrade to
392 1.5 first. The upgrade script maintenance/upgrade1_5.php has been removed
393 with MediaWiki 1.21.
394
395 Don't forget to always back up your database before upgrading!
396
397 See the file UPGRADE for more detailed upgrade instructions.
398
399 For notes on 1.24.x and older releases, see HISTORY.
400
401 == Online documentation ==
402
403 Documentation for both end-users and site administrators is available on
404 MediaWiki.org, and is covered under the GNU Free Documentation License (except
405 for pages that explicitly state that their contents are in the public domain):
406
407 https://www.mediawiki.org/wiki/Documentation
408
409 == Mailing list ==
410
411 A mailing list is available for MediaWiki user support and discussion:
412
413 https://lists.wikimedia.org/mailman/listinfo/mediawiki-l
414
415 A low-traffic announcements-only list is also available:
416
417 https://lists.wikimedia.org/mailman/listinfo/mediawiki-announce
418
419 It's highly recommended that you sign up for one of these lists if you're
420 going to run a public MediaWiki, so you can be notified of security fixes.
421
422 == IRC help ==
423
424 There's usually someone online in #mediawiki on irc.freenode.net.