Misskey/Sharkey has a lot of optional services by default. These are not self hosted or managed by the instance administrator apart from an api token. Some examples:
1) hCaptcha/recaptcha/mcaptcha/turnstile Not every misskey/sharkey instance utilizes the hCaptcha service but some do in order to prevent bots. If you have followed me for a bit (on my old account i still need to migrate the clip itself) you'll be aware I have a collection of horrible inaccessible captchas. I use the clip to highlight the issue with modern captchas (showcasing how they can be inaccessible).
2) SMTP/Email There is an integration with third party email providers (I don't remember this particular email configuration for the instance I'll have to check with kio because he set it up for me). This is a completely optional service that relies on third parties for processing things (such as noreply@transfem.org).
3) DeepL translation I use the free tier of DeepL translation on this instance (I don't manage this, it is an api key i fed into sharkey that makes requests using that token on my behalf). It's an optional service that I had disabled prior because the previous api key was revoked.
Now, with that out of the way... What is the PR actually doing? Well, a while ago we had this issue with hetzner. One of the things that Germany requires is that if you are hosting pornographic content that you must verify the age of all your users. This is why woem.men (when they considered specific images and the instance as a whole) was threatened by hetzner. To hetzner's perspective woem.men was operating as an adult website without proper verification in place and therefore a liability. Now, woem.men isn't strictly for that but lewd.lgbt is and so is kitsunes.gay. These are two instances that I have been involved with that are focused on adult only content. I want to talk about how kitsuverify works and how that led into this PR...
Kitsuverify is what Kio has named a service that he made himself. What it does is that if there is reasonable suspicion someone is a minor we can put in the moderation notes "ADM/ID" to request additional verification through stripe. Most of the time, people who have 18+ in bio and who don't specify "I am a minor" do not ever go through the ID/Age verification process. This is reserved for people who have stated they are a minor, or for instance administrators (it was a bit insulting to go through age verification for my boyfriend's instance but i did). All the PR is doing is trying to add that same sort of functionality with stripe into sharkey as an OPTIONAL service that is disabled by default (you have to provide your own api tokens, it's also a billable thing kio gets billed every id that is processed). This is not "normalizing ID verification" this is trying to host adult only spaces in a legally compliant manner (at least back when they were on hetzner). You are free to keep this disabled on your instance, and I am not going to enable it for transfem.social because this is not an adult content orientated instance. We allow adult content sure, but it's a general purpose instance and not locked down to an adult only space like kitsunes.gay and lewd.lgbt are. Please stop harassing the lead maintainer of sharkey over this, it was a group decision that we thought would be a good idea to help server operators run adult instances in Europe and places that require ID verification.
EDIT: To be clear, Hetzner does not allow adult content period. It doesn't change the fact Germany requires ID verification for adult websites. It is probably why they do not want to allow adult content on their platform as ensuring everyone is compliant would be a headache for a service provider.
@puppygirlhornypost2 thanks for clarifying I have no objection to individual instances enabling this for legal compliance, they obviously have no choice, so there's no point debating this
my question is: what's the benefit of having this in mainline sharkey? is it a huge maintenance burden for individual instances to keep in their forks? is this implementation carefully designed to maximize privacy and discourage instances from rolling their own sloppy solutions?
regardless of necessity, it still feels uncomfortable to integrate such a feature into the mainline ("normalize" or not, that's still the sharkey project facilitating this practice, rather than instances acting at their own discretion) but if there's a good reason for it that's not just "because we can" then that would be reassuring
@jeder@novenary it is a pretty big burden tbh, I get the module idea (I love modules I talked to Zotan and iceshrimp contributors along with Hazel who wrote the discussion because I was still scared to dip my toes in the water). Unfortunately upstream misskey does not have server side modules and it would be a substantial amount of effort exceeding the capability of the sharkey team. In fact it was discussed redoing sharkey to be more like a modloader that injects into base misskey… unfortunately JavaScript/typescript does not have the niceties a language such as C# or Java have with dependency injection, reflection and other features related to isolation with App Contexts. It is theoretically possible but would be a substantial amount of effort to do right, and that makes you ask the question "why continue with the ts codebase then". Defeating the fork and moving towards rewriting the software from scratch…
@jeder@puppygirlhornypost2 that doesn't prevent the feature from being maintained as a separate patch or soft-fork
I would expect instances large enough to even think about enabling this have technically competent staff that would know how to deploy it even if they're not writing the patch themselves
@novenary@puppygirlhornypost2 we all know how separate patches/forks end up dead, fast, because someone lost interest in software and/or got bullied into it
@jeder@novenary my technical competency is irrelevant to the fact I do not care enough to maintain a typescript/JavaScript codebase that is mostly incomprehensible and the documentation for it if there is any at all (which no for the majority of it no) is in fucking Japanese. I am trying to migrate this larger instance >1,600 users over to base sharkey… but also I am not going to be utilizing this service so I don’t actually have a stake there. All our fork does is modify the instance icon in a select few areas (I have a gitlab issue to allow customization for this because I am sick and tired of seeing forks of a fork of a fork for a minor change like instance branding that is pathetic) and even still I think it’s too much of a maintenance burden to continue keeping it "in house". It doesn’t help that the person who made it originally fired me from the instance before it was bought out from her by my friends and then I became the head admin. Do you think I can just slide into her dms and ask "hey I know you despise me but can you tell me why you did this in the custom fork"
@novenary@puppygirlhornypost2 tbh the fact that she did a fucking fork just to change a bunch of icons instead, of, you know, making it configurable, is beyond my mind
@jeder@novenary the fact she was the fucking lead maintainer of sharkey when she forked sharkey to introduce branding changes is also a mind fuck believe me
@jeder@novenary like there's a difference between the misskey io fork being made by people who are not syuilo and then syuilo just committing epic changes to the misskey io fork such as patching the memory leak from upstream and not contributing it back to upstream (i am still pissed about this, especially after hazel busted her ass to come up with a fix to find the code was in misskeyio's private fork)
@jeder@novenary it's an example of why someone making such large modifications to the software is a sore subject - the misskeyio fork does various changes (improvements such as extending role permissions, fixing memory leaks and concurrency issues) while giving the middle finger back to upstream and leaving them to rot.
@mikoto@novenary@jeder iceshrimp.NET is very cool and i talk to the devs all the time it's wonderful. Going back to our earlier conversation about plugins, iceshrimp.NET does have full class plugin support (and i have several people who want to add misc things like my gf lexi who wants to do some funky stuff). In C# it's a lot easier to do assembly loading with specific contexts, there's reflection and dependency injection as part of the language (I mean exposed by Microsoft packages but w/e). It's just a lot easier to do that in an architecture that isn't based on node & ts/js.
@mikoto@novenary@jeder There was discussion about sharkey maybe becoming a plugin loader but it was ruled out as it's too hard to maintain. I have no interest in migrating my sharkey instances over to iceshrimp.NET. iceshrimp.NET is not a drop in replacement for sharkey, i do want an iceshrimp.NET instance that isn't just my staging bench but that would be under a different domain arfarf.me and would be for users who want that experience instead of forcing it down the throat of this instance's users who are used to sharkey and use the instance because it's a sharkey instance.
@puppygirlhornypost2@jeder@novenary migrating between database schemas is an absolute nightmare from the few times I've seen other instances do that. And also yeah, it's really not the same experience.
@puppygirlhornypost2@mikoto@jeder tbh I don't think reflection can reasonably be called a plugin API :P it's just monkeypatching the code at runtime and we know how well that went for firefox but I can see how a fresh and clean code base would be easier to make extensible correctly
@puppygirlhornypost2@jeder@novenary the funniest thing for me is that some of the transfem social sharkey fork are basically reverting unwanted sharkey changes, like the fucking boost icon (sharkey was the one who changed it to rocket originally, then firefiah copied it)
Like she was maintaining it, but doing it upstream? Nah
totally isn’t patching sharkey on her instance to do that as well
@alice@jeder@novenary personally i like the renote icon... the rocket one is too confusing (it was something people were very confused about during tumblr migration)
@puppygirlhornypost2@jeder@novenary exactly, sharkey changed refresh renote to rocket, with sharkey maintainers being “this is obviously better, get used to it”, and then a sharkey maintainer reverts it back to refresh in her instance-specific fork…
I also like refresh one better, and change it for my instance, but upstream is still rocket afaik
@puppygirlhornypost2@jeder@novenary rocket is also objectively less polished because 1. They forgot to change it for “mute boosts” and 2. It’s the same icon as for non-federated posts