2018-04-17 18:24:01 +00:00
|
|
|
== MediaWiki 1.32 ==
|
|
|
|
|
|
|
|
|
|
THIS IS NOT A RELEASE YET
|
|
|
|
|
|
|
|
|
|
MediaWiki 1.32 is an alpha-quality branch and is not recommended for use in
|
|
|
|
|
production.
|
|
|
|
|
|
|
|
|
|
=== Configuration changes in 1.32 ===
|
2018-05-04 18:31:16 +00:00
|
|
|
* (T115414) The $wgEnableAPI and $wgEnableWriteAPI settings, deprecated in 1.31,
|
|
|
|
|
have been removed.
|
2018-04-16 23:26:48 +00:00
|
|
|
* The $wgUseAjax setting, deprecated in 1.31, is now ignored.
|
2018-04-18 16:05:52 +00:00
|
|
|
* The $wgSiteSupportPage setting, unused since 1.5, was removed.
|
2018-05-04 18:31:16 +00:00
|
|
|
* The default quality of JPEG thumbnails generated by GD was reduced from 95 to
|
|
|
|
|
80. The quality of JPEG thumbnails is now configurable through the new setting
|
2018-05-07 19:36:20 +00:00
|
|
|
$wgJpegQuality (default 80). This aligns the quality to what ImageMagick uses.
|
2018-05-04 18:31:16 +00:00
|
|
|
* $wgExperimentalHtmlIds, deprecated since 1.30, has been removed. The
|
|
|
|
|
'html5-legacy' value for $wgFragmentMode is no longer accepted.
|
2018-05-07 08:34:13 +00:00
|
|
|
* The experimental Html5Internal and Html5Depurate tidy drivers were removed.
|
|
|
|
|
RemexHtml, which is the default, should be used instead.
|
Initial support for Content Security Policy, disabled by default
The primary goal here is a defense in depth measure to
stop an attacker who found a bug in the parser allowing
them to insert malicious attributes.
This wouldn't stop someone who could insert a full
script tag (since at current it can't distinguish between
malicious and legit user js). It also would not prevent
DOM-based or reflected XSS for anons, as the nonce value
is guessable for anons when receiving a response cached
by varnish. However, the limited protection of just stopping
stored XSS where the attacker only has control of attributes,
is still a big win in my opinion. (But it wouldn't prevent
someone who has that type of xss from abusing things like
data-ooui attribute).
This will likely break many gadgets. Its expected that any
sort of rollout on Wikimedia will be done very slowly, with
lots of testing and the report-only option to begin with.
This is behind feature flags that are off by default, so
merging this patch should not cause any change in default
behaviour.
This may break some extensions (The most obvious one
is charinsert (See fe648d41005), but will probably need
some testing in report-only mode to see if anything else breaks)
This uses the unsafe-eval option of CSP, in order to
support RL's local storage thingy. For better security,
we may want to remove some of the sillier uses of eval
(e.g. jquery.ui.datepicker.js).
For more info, see spec: https://www.w3.org/TR/CSP2/
Additionally see:
https://www.mediawiki.org/wiki/Requests_for_comment/Content-Security-Policy
Bug: T135963
Change-Id: I80f6f469ba4c0b608385483457df96ccb7429ae5
2016-02-29 04:13:10 +00:00
|
|
|
* (T135963) You can now define a Content Security Policy for your wiki. This
|
|
|
|
|
adds a defense-in-depth feature to stop an attacker who has found a bug in
|
|
|
|
|
the parser allowing them to insert malicious attributes. Disabled by default,
|
|
|
|
|
you can configure this via $wgCSPHeader and $wgCSPReportOnlyHeader.
|
2018-04-17 18:24:01 +00:00
|
|
|
|
|
|
|
|
=== New features in 1.32 ===
|
2017-02-28 20:52:17 +00:00
|
|
|
* (T112474) Generalized the ResourceLoader mechanism for overriding modules
|
|
|
|
|
using a particular page during edit previews.
|
|
|
|
|
* Added 'ApiParseMakeOutputPage' hook.
|
2017-08-28 16:45:49 +00:00
|
|
|
* (T174313) Added checkbox on Special:ListUsers to display only users in temporary
|
|
|
|
|
user groups.
|
2018-04-17 18:24:01 +00:00
|
|
|
|
|
|
|
|
=== External library changes in 1.32 ===
|
|
|
|
|
* …
|
|
|
|
|
|
|
|
|
|
==== Upgraded external libraries ====
|
2018-05-01 20:04:21 +00:00
|
|
|
* Updated QUnit from 2.4.0 to 2.6.0.
|
2018-04-17 18:24:01 +00:00
|
|
|
|
|
|
|
|
==== New external libraries ====
|
|
|
|
|
* …
|
|
|
|
|
|
|
|
|
|
==== Removed and replaced external libraries ====
|
|
|
|
|
* …
|
|
|
|
|
|
|
|
|
|
=== Bug fixes in 1.32 ===
|
|
|
|
|
* …
|
|
|
|
|
|
|
|
|
|
=== Action API changes in 1.32 ===
|
2018-04-04 20:22:01 +00:00
|
|
|
* Added templated parameters.
|
|
|
|
|
* A module can define a templated parameter like "{fruit}-quantity", where
|
|
|
|
|
the actual parameters recognized correspond to the values of a multi-valued
|
|
|
|
|
parameter. Then clients can make requests like
|
|
|
|
|
"fruits=apples|bananas&apples-quantity=1&bananas-quantity=5".
|
|
|
|
|
* action=paraminfo will return templated parameter definitions separately
|
|
|
|
|
from normal parameters. All parameter definitions now include an "index"
|
|
|
|
|
key to allow clients to maintain parameter ordering when merging normal and
|
|
|
|
|
templated parameters.
|
2018-04-17 18:24:01 +00:00
|
|
|
|
|
|
|
|
=== Action API internal changes in 1.32 ===
|
2017-02-28 20:52:17 +00:00
|
|
|
* Added 'ApiParseMakeOutputPage' hook.
|
2018-04-04 20:22:01 +00:00
|
|
|
* Parameter names may no longer contain '{' or '}', as these are now used for
|
|
|
|
|
templated parameters.
|
2018-04-17 18:24:01 +00:00
|
|
|
|
|
|
|
|
=== Languages updated in 1.32 ===
|
2018-05-04 18:31:16 +00:00
|
|
|
MediaWiki supports over 350 languages. Many localisations are updated regularly.
|
|
|
|
|
Below only new and removed languages are listed, as well as changes to languages
|
|
|
|
|
because of Phabricator reports.
|
2018-04-17 18:24:01 +00:00
|
|
|
|
2018-05-02 09:37:28 +00:00
|
|
|
* (T193566) Added language support for Ambonese Malay (abs).
|
2018-04-17 18:24:01 +00:00
|
|
|
|
|
|
|
|
=== Breaking changes in 1.32 ===
|
2018-05-04 18:31:16 +00:00
|
|
|
* $wgRequestTime, deprecated in 1.25, was removed. Use
|
|
|
|
|
$_SERVER['REQUEST_TIME_FLOAT'] or WebRequest::getElapsedTime() instead.
|
|
|
|
|
* The MediaWikiI18N class, deprecated in 1.31, was removed.
|
|
|
|
|
* QuickTemplate::setTranslator(), deprecated in 1.31, was removed. Use
|
|
|
|
|
Skin::msg() instead.
|
|
|
|
|
* wfInitShellLocale(), deprecated in 1.30, was removed.
|
|
|
|
|
* wfShellExecDisabled(), deprecated in 1.30, was removed.
|
|
|
|
|
* The type string for the parameter $lang of DateFormatter::getInstance,
|
|
|
|
|
deprecated in 1.31, was removed.
|
|
|
|
|
* The EDIT_TOKEN_SUFFIX constant deprecated in 1.27, was removed. Use
|
|
|
|
|
MediaWiki\Session\Token::SUFFIX instead.
|
|
|
|
|
* EditPage::isOouiEnabled() deprecated in 1.30, was removed.
|
|
|
|
|
* mw.util.wikiGetlink(), deprecated in 1.23, was removed. Use mw.util.getUrl()
|
|
|
|
|
instead.
|
|
|
|
|
* (T61113) The following methods and constants from the Revision class, which
|
|
|
|
|
were deprecated in 1.25, have now been removed:
|
2018-05-02 19:32:38 +00:00
|
|
|
* Revision::getRawUser()
|
|
|
|
|
* Revision::getRawUserText()
|
|
|
|
|
* Revision::getRawComment()
|
2018-05-04 18:31:16 +00:00
|
|
|
* window.gM() from mediawiki.jqueryMsg, deprecated in 1.23, was removed. Use
|
|
|
|
|
mw.msg() or mw.message() instead.
|
2018-05-04 18:33:33 +00:00
|
|
|
* mw.util.escapeId(), deprecated in 1.30, was removed. Use
|
|
|
|
|
mw.util.escapeIdForAttribute or mw.util.escapeIdForLink instead.
|
2018-05-04 18:37:46 +00:00
|
|
|
* mw.util.updateTooltipAccessKeys(), deprecated in 1.24, was removed. Use
|
|
|
|
|
jquery.accessKeyLabel instead.
|
2018-05-02 19:42:56 +00:00
|
|
|
* The SqlDataUpdate class, deprecated in 1.28, has been removed.
|
2018-05-07 08:34:13 +00:00
|
|
|
* The Html5Internal and Html5Depurate tidy driver classes were removed, along with the
|
|
|
|
|
Balancer tidy implementation. Both implementations were experimental, and were replaced
|
|
|
|
|
by RemexHtml.
|
2018-04-17 18:24:01 +00:00
|
|
|
|
|
|
|
|
=== Deprecations in 1.32 ===
|
2018-04-17 21:29:36 +00:00
|
|
|
* Use of a StartProfiler.php file is deprecated in favour of placing
|
|
|
|
|
configuration in LocalSettings.php.
|
2018-04-25 22:13:03 +00:00
|
|
|
* HTMLForm::setSubmitProgressive() is deprecated. No need to call it. Submit
|
|
|
|
|
button is already marked as progressive.
|
2018-04-24 23:22:00 +00:00
|
|
|
* Skin::setupSkinUserCss() is deprecated. Adding of modules to load
|
|
|
|
|
has been centralised to Skin::getDefaultModules(), which is now capable
|
|
|
|
|
of queueing style modules as well.
|
2018-05-04 18:31:16 +00:00
|
|
|
* OutputPage::addModuleScripts() and ParserOutput::addModuleScripts are
|
|
|
|
|
deprecated. Use addModules() instead.
|
2018-05-10 20:52:47 +00:00
|
|
|
* Overriding SearchEngine::{searchText,searchTitle,searchArchiveTitle}
|
|
|
|
|
in extending classes is deprecated. Extend related doSearch* methods
|
|
|
|
|
instead.
|
2018-05-18 14:44:18 +00:00
|
|
|
* CollationFa has been removed completely as it's not needed anymore
|
2018-04-17 18:24:01 +00:00
|
|
|
|
|
|
|
|
=== Other changes in 1.32 ===
|
2017-11-25 20:02:55 +00:00
|
|
|
* Soft hyphens (U+00AD) are now automatically removed from titles; these
|
|
|
|
|
characters can accidentally end up in copy-and-pasted titles.
|
2018-03-22 10:48:55 +00:00
|
|
|
* Strip Unicode 6.3.0 directional formatting characters (U+061C, U+2066,
|
|
|
|
|
U+2067, U+2068, U+2069) from the title.
|
2018-04-17 18:24:01 +00:00
|
|
|
* …
|
|
|
|
|
|
|
|
|
|
== Compatibility ==
|
2018-05-04 18:31:16 +00:00
|
|
|
MediaWiki 1.32 requires PHP 5.5.9 or later. Although HHVM 3.18.5 or later is
|
|
|
|
|
supported, it is generally advised to use PHP 5.5.9 or later for long term
|
|
|
|
|
support.
|
2018-04-17 18:24:01 +00:00
|
|
|
|
|
|
|
|
MySQL/MariaDB is the recommended DBMS. PostgreSQL or SQLite can also be used,
|
|
|
|
|
but support for them is somewhat less mature. There is experimental support for
|
|
|
|
|
Oracle and Microsoft SQL Server.
|
|
|
|
|
|
|
|
|
|
The supported versions are:
|
|
|
|
|
|
2018-04-18 21:23:27 +00:00
|
|
|
* MySQL 5.5.8 or later
|
2018-04-17 18:24:01 +00:00
|
|
|
* PostgreSQL 9.2 or later
|
|
|
|
|
* SQLite 3.3.7 or later
|
|
|
|
|
* Oracle 9.0.1 or later
|
|
|
|
|
* Microsoft SQL Server 2005 (9.00.1399)
|
|
|
|
|
|
|
|
|
|
== Upgrading ==
|
|
|
|
|
1.32 has several database changes since 1.31, and will not work without schema
|
|
|
|
|
updates. Note that due to changes to some very large tables like the revision
|
|
|
|
|
table, the schema update may take quite long (minutes on a medium sized site,
|
|
|
|
|
many hours on a large site).
|
|
|
|
|
|
|
|
|
|
Don't forget to always back up your database before upgrading!
|
|
|
|
|
|
|
|
|
|
See the file UPGRADE for more detailed upgrade instructions, including
|
|
|
|
|
important information when upgrading from versions prior to 1.11.
|
|
|
|
|
|
|
|
|
|
For notes on 1.31.x and older releases, see HISTORY.
|
|
|
|
|
|
|
|
|
|
== Online documentation ==
|
|
|
|
|
Documentation for both end-users and site administrators is available on
|
|
|
|
|
MediaWiki.org, and is covered under the GNU Free Documentation License (except
|
|
|
|
|
for pages that explicitly state that their contents are in the public domain):
|
|
|
|
|
|
|
|
|
|
https://www.mediawiki.org/wiki/Special:MyLanguage/Documentation
|
|
|
|
|
|
|
|
|
|
== Mailing list ==
|
|
|
|
|
A mailing list is available for MediaWiki user support and discussion:
|
|
|
|
|
|
|
|
|
|
https://lists.wikimedia.org/mailman/listinfo/mediawiki-l
|
|
|
|
|
|
|
|
|
|
A low-traffic announcements-only list is also available:
|
|
|
|
|
|
|
|
|
|
https://lists.wikimedia.org/mailman/listinfo/mediawiki-announce
|
|
|
|
|
|
|
|
|
|
It's highly recommended that you sign up for one of these lists if you're
|
|
|
|
|
going to run a public MediaWiki, so you can be notified of security fixes.
|
|
|
|
|
|
|
|
|
|
== IRC help ==
|
|
|
|
|
There's usually someone online in #mediawiki on irc.freenode.net.
|