User: Mostly remove password handling
[lhc/web/wiklou.git] / RELEASE-NOTES-1.27
1 Security reminder: If you have PHP's register_globals option set, you must
2 turn it off. MediaWiki will not work with it enabled.
3
4 == MediaWiki 1.27 ==
5
6 THIS IS NOT A RELEASE YET
7
8 MediaWiki 1.27 is an alpha-quality branch and is not recommended for use in
9 production.
10
11 === Configuration changes in 1.27 ===
12 * Removed $wgUseLinkNamespaceDBFields
13 * Deprecated $wgResourceLoaderMinifierStatementsOnOwnLine and
14 $wgResourceLoaderMinifierMaxLineLength, because there was little value in
15 making the behavior configurable. The default values (`false` for the former,
16 1000 for the latter) are now hard-coded.
17 * $wgDebugDumpSqlLength was removed (deprecated in 1.24).
18 * $wgDebugDBTransactions was removed (deprecated in 1.20).
19 * $wgRemoteUploadTarget (added in 1.26) removed, replaced by $wgForeignUploadTargets
20 * $wgUseXVO has been removed, as it provides functionality only used by
21 custom Wikimedia patches against Squid 2.x that probably noone uses in
22 production anymore. There is now $wgUseKeyHeader that provides similar
23 functionality but instead of the MediaWiki-specific X-Vary-Options header,
24 uses the draft Key header standard.
25 * $wgScriptExtension (and support for '.php5' entry points) was removed. See the
26 deprecation notice in the release notes for version 1.25 for advice on how to
27 preserve support for '.php5' entry points via URL rewriting.
28 * Password handling via the User object has been deprecated and partially
29 removed, pending the future introduction of AuthManager. In particular:
30 ** expirePassword(), getPasswordExpireDate(), resetPasswordExpiration(), and
31 getPasswordExpired() have been removed. They were unused outside of core.
32 ** The mPassword, mNewpassword, mNewpassTime, and mPasswordExpires fields are
33 now private and will be removed in the future.
34 ** The getPassword() and getTemporaryPassword() methods now throw
35 BadMethodCallException and will be removed in the future.
36 ** The ability to pass 'password' and 'newpassword' to createNew() has been
37 removed. The only users of it seem to have been using it to set invalid
38 passwords, and so shouldn't be greatly affected.
39 ** setPassword(), setInternalPassword(), and setNewpassword() have been
40 deprecated, pending the introduction of AuthManager.
41 ** User::randomPassword() is deprecated in favor of a new method
42 PasswordFactory::generateRandomPasswordString()
43 ** User::getPasswordFactory() is deprecated, callers should just create a
44 PasswordFactory themselves.
45 ** A new constructor, User::newSystemUser(), has been added to simplify the
46 creation of passwordless "system" users for logged actions.
47
48 === New features in 1.27 ===
49 * $wgDataCenterId and $wgDataCenterRoles where added, which will serve as
50 basic configuration settings needed for multi-datacenter setups.
51 $wgDataCenterUpdateStickTTL was also added.
52 * Added a new hook, 'UserMailerTransformContent', to transform the contents
53 of an email. This is similar to the EmailUser hook but applies to all mail
54 sent via UserMailer.
55 * Added a new hook, 'UserMailerTransformMessage', to transform the contents
56 of an emai after MIME encoding.
57 * Added a new hook, 'UserMailerSplitTo', to control which users have to be
58 emailed separately (ie. there is a single address in the To: field) so
59 user-specific changes to the email can be applied safely.
60 * $wgCdnMaxageLagged was added, which limits the CDN cache TTL
61 when any load balancer uses a DB that is lagged beyond the 'max lag'
62 setting in the relevant section of $wgLBFactoryConf.
63 * Added several JavaScript libraries for uploading files to MediaWiki
64 from the client-side. See documentation for mw.Upload and its
65 subclasses for more information.
66 * Added OOUI dialogs and layout for file upload interfaces. See
67 documentation for mw.Upload.Dialog, mw.Upload.BookletLayout and its
68 subclasses for more information.
69 * User::newSystemUser() may be used to simplify the creation of passwordless
70 "system" users for logged actions from scripts and extensions.
71
72 ==== External libraries ====
73
74 === Bug fixes in 1.27 ===
75
76 === Action API changes in 1.27 ===
77 * Added list=allrevisions.
78 * generator=recentchanges now has the option to generate revids.
79 * ApiPageSet::setRedirectMergePolicy() was added. This allows generator
80 modules to define how generator data for a redirect source gets merged
81 into the redirect destination.
82 * prop=imageinfo&iiprop=uploadwarning will no longer include the possibility of
83 "was-deleted" warning.
84
85 === Action API internal changes in 1.27 ===
86
87 === Languages updated in 1.27 ===
88
89 MediaWiki supports over 350 languages. Many localisations are updated
90 regularly. Below only new and removed languages are listed, as well as
91 changes to languages because of Bugzilla reports.
92
93 === Other changes in 1.27 ===
94
95 == Compatibility ==
96
97 MediaWiki 1.27 requires PHP 5.3.3 or later. There is experimental support for
98 HHVM 3.3.0.
99
100 MySQL is the recommended DBMS. PostgreSQL or SQLite can also be used, but
101 support for them is somewhat less mature. There is experimental support for
102 Oracle and Microsoft SQL Server.
103
104 The supported versions are:
105
106 * MySQL 5.0.3 or later
107 * PostgreSQL 8.3 or later
108 * SQLite 3.3.7 or later
109 * Oracle 9.0.1 or later
110 * Microsoft SQL Server 2005 (9.00.1399)
111
112 == Upgrading ==
113
114 1.27 has several database changes since 1.26, and will not work without schema
115 updates. Note that due to changes to some very large tables like the revision
116 table, the schema update may take quite long (minutes on a medium sized site,
117 many hours on a large site).
118
119 If upgrading from before 1.11, and you are using a wiki as a commons
120 repository, make sure that it is updated as well. Otherwise, errors may arise
121 due to database schema changes.
122
123 If upgrading from before 1.7, you may want to run refreshLinks.php to ensure
124 new database fields are filled with data.
125
126 If you are upgrading from MediaWiki 1.4.x or earlier, you should upgrade to
127 1.5 first. The upgrade script maintenance/upgrade1_5.php has been removed
128 with MediaWiki 1.21.
129
130 Don't forget to always back up your database before upgrading!
131
132 See the file UPGRADE for more detailed upgrade instructions.
133
134 For notes on 1.26.x and older releases, see HISTORY.
135
136 == Online documentation ==
137
138 Documentation for both end-users and site administrators is available on
139 MediaWiki.org, and is covered under the GNU Free Documentation License (except
140 for pages that explicitly state that their contents are in the public domain):
141
142 https://www.mediawiki.org/wiki/Documentation
143
144 == Mailing list ==
145
146 A mailing list is available for MediaWiki user support and discussion:
147
148 https://lists.wikimedia.org/mailman/listinfo/mediawiki-l
149
150 A low-traffic announcements-only list is also available:
151
152 https://lists.wikimedia.org/mailman/listinfo/mediawiki-announce
153
154 It's highly recommended that you sign up for one of these lists if you're
155 going to run a public MediaWiki, so you can be notified of security fixes.
156
157 == IRC help ==
158
159 There's usually someone online in #mediawiki on irc.freenode.net.