Current problem
Currently, the send messages permission covers send, edit, and delete, of messages sent in a channel.
Proposed change
Splitting out the "edit" and "delete" messages permissions as options in the Role settings in a community.
This allows channels to be one-way write, so that things such as "edit trolling", sneaky behavior, or otherwise disruptive activities can be limited in either channels, categories, or an entire community.
The clear technical reason for this is making existing ACLs as granular as possible on a technical level.
Additional information
The core motivation behind this is: there should be as granular controls as possible for features in community admin/owners' hands. Splitting out the "send/edit/delete message" ACL is a valid technical decision and a good one.
This is also important for channels, categories, or communities where it is important that people "stand behind what they say".
Maybe a one-time notice should be shown to the user when entering such a channel with such settings -- "note: you can not edit" or "note: you can not delete messages in this channel" -- similar to the "note: nsfw content" dialog that appears before opening an nsfw channel for the first time?
additionally, could it be possible to have an "edit" and "delete" timer setting -- so that in case an admin wants a channel to have "5 minutes of edit permission" or "5 minutes of delete permission", it's possible? as in, a time after sending a message, that messages can be edited or deleted? from seconds to minutes to hours to days. One example is to again prevent edit trolling.
23 comments
Comment by @fluxerhost
Comment by @Shardion
- It significantly reduces usability, by restricting the editing and deleting of messages
- But, it only affects people who often revise or make mistakes with their messages (me), which may not be the same people who are at the levers to enable it
- It is controlled by community administrators, and there is no way to get around it, beyond pleading to them to have it removed
Given the above, I believe that, in its current form, this should not be a feature which Fluxer offers. One of three explicitly-mentioned use cases is to prevent "edit trolling", which I do not see as an issue that Fluxer should attempt to solve. This is a social issue, and technical measures scarcely solve the underlying tensions that cause social issues, so, it should be the job of moderators to take reports, spot edit trolling, and maybe tell the problematic users to cut it out. The idea of a channel where users must "stand behind what they say" feels like a poor one. I don't see a point to it, beyond inviting harassment, and forcing any messages to permanently mark someone, short of having them delete their account. Giveaways, and other systems requiring one unchanging entry, would probably be a legitimate use for this, but, bots already exist to provide systems like this, so I don't think it will be worth the potential harm, and effort to implement. A one-time notice is easily ignored, and users may have seen and subsequently forgotten about it, even before the edit-blocking becomes relevant to them. It does not otherwise do anything to resolve the issues with edit-blocking, so I don't think it's sufficient to let this feature exist. Blocking edits and deletions also interacts poorly with the user's right to be forgotten, as it were. One of Fluxer's goals is to have better data privacy than Discord, and that comes with the option to delete anything, at any time. It would be possible to have users be unable to delete individual messages, only deleting them in bulk deletions of entire channels or communities, but, given the concept of adding a one-time notice, there is an implication that these channels are meant to be sectioned-off spaces, where users do not frequently post. I doubt that users will mind losing one or two other messages, if it gives them the option to delete something that they said, resulting in everyone using the bulk deletion route to circumvent the permission. I doubt that a time window which allows edits and deletions will help, since I personally edit and delete messages long after, say, five minutes have passed since their sending. This is often to correct typos, which is arguably not important, but also to update information in living messages, ones that are pinned or linked to in some form.Comment by @fluxerhost
Comment by @Shardion
Comment by @fluxerhost
Comment by @Amarielique
Comment by @fluxerhost
Comment by @Shardion
Comment by @fluxerhost
Comment by @ElliotJ09
Comment by @fluxerhost
Comment by @Shardion
Comment by @fluxerhost
Comment by @vkyfox
@everyoneto write in most channels, that would probably be a bad idea, and the users, dissatisfied and rightfully so, would probably be upset and leave. I think this discussed toggle is very much the same thing. It should not be used in most cases, and limits and aspect of chatting we have come to expect. Does it mean that it shouldn't exist? I don't think so. As for safety and privacy concern, as well as claims of oppressive behaviour, I think they are exaggerated. Nothing in removing the ability to edit or delete your messages prevents you from clarifying your point of view in subsequent messages, or correcting mistakes in the same way. Very much the same as day-to-day social behaviour, be it mails, letters, talking or whatnot. Most means of communication do not allow for retroactively changing your words, and most of them do okay as means of communication regardless. I personally don't think you need to be able to edit your messages to be understood. Again, I think removing the ability to edit or delete your messages should be very rare and limited to very specific use-cases; much like many other permissions; but while I agree that this toggle should most often not be used is not, in my opinion, an argument for the toggle not to exist.Comment by @fluxerhost
Example use case for this feature: running fluxer in a corporate setting, or for a law firm.
"Legal discovery" and evidence preservation for all messages must be preserved. If an employee leaves or is fired, they don't get to take their messages with them. If an employee is involved in a corporate investigation (e.g. harassment), the investigations team should be able to extract all messages sent by the user. Message immutability via expanded ACLs is a good first step to support such safety. It is more technically complex, but also a good idea, to preserve all edit and delete history, however it is also a good feature and easy to implement to add message immutability/making the ACLs around messages more granular.Comment by @Shardion
Comment by @fluxerhost
Comment by @Shardion
Comment by @fluxerhost
Comment by @Shardion
Comment by @fluxerhost
Comment by @fluxerhost
Comment by @Shardion
- Create an environment that encourages harassment (the "stand by what you say" idea)
- Prevent users from burying things, or otherwise leaving them in the past
- Make it more difficult for users to leave a community, by forcing them to take all or none of their messages with them
- Admins enable because they, somehow, like it better that way
And, the original concern, of making the platform significantly less usable for a subset of people, still stands. I don't think any of the provided remediations for these issues are effective.- A scare screen would be in opposition to regular use for a channel. Either the scare screen is reduced to the point of ineffectiveness, or it is sufficiently annoying to obstruct general discussion. Given the issue of alarm fatigue, I don't think there can be a good middle-ground in designing a scare screen like this, but there hasn't been any user testing, so that might not be true.
- An alternate design might, alongside a scare screen, have a little notice in the bottom right, like the slowmode indicator. If you do want to do user testing, try adding that...!
- Edit slowmode either doesn't do anything to stop edit trolling, if you can edit once after sending a message, or, if you can't, obstructs significant real editing usage, like typo corrections and adding context. It also doesn't do anything to solve edit trolling if the slowmode duration is too short, since you can just wait, say, one minute, then edit the message like normal.
- Edit windows are probably the best idea here, but there are still valid reasons to edit a message, say, five minutes after it's been sent. It might be a low-traffic channel with long messages, like many of the topic channels in Fluxer Labs, or it might be a living message, pinned or linked to, which would benefit from being updated long after its initial sending.
- Making it exclusive to self-hosted instances has been discussed at length, and I won't bother to repeat it here. Everything that Fluxer (software) can do becomes a part of Fluxer (platform), as soon as federation is involved, so I don't think this is sufficient to stop misuse, and Fluxer Platform AB is at least partially responsible for what features they allow on Fluxer (platform). If Fluxer.com were to choose not to enable this feature, that means there is a significant reason behind the choice, as the default choice is lower-friction, and gives broader access to more features of Fluxer (software). Nobody has posed objections which are not related to safety or data privacy, so it is a rather safe to assume that those are the reasons.
- Sure, you can choose to leave communities and instances that enable this, but that means you're being excluded from them. It would be best to not hand out access to levers that exclude people. Some people would pull it for fun, others would pull it out of malice, but you know that someone is definitely going to pull it.
I also do not accept that the ability to disable message deletion is OK, purely because you can choose to leave a community and delete all of your messages. That adds a lot of friction to what should be a simple action of deleting a single message, which ultimately requires a choice by the user: assuming they can even rejoin the community, do they value getting rid of that one message more than all of the messages they've sent there? You might be surprised by how little attachment users have to their messages, and I, personally, would probably choose to get rid of everything. If anyone chooses to do that, the purpose of the permission has been defeated, and you lost context in previous conversations, and records of real participation in your community. I ultimately believe that these features go against one of Fluxer's goals, to enable easier data privacy for all users. It should be as easy as possible to control exactly what data you have on Fluxer, who can see that data, and what the data they see is. The ability to disable editing or deletion in a channel would, completely unnecessarily, make it more difficult, in service of use-cases that are either already covered by existing solutions, or already obstructed by non-optional features of Fluxer. There is also the potential (the only thing there can be, since the feature doesn't exist yet) for harm, and a significant impact to usability. I have raised the alternative solution, of a Fluxer fork, "Business Fluxer", which adds the feature, and removes support for federation with standard Fluxer, in a way that is not trivially reversible. Ideally, it would be maintained by businesses that require it, or even officially, by Fluxer Platform AB. This fork would already be necessary to use Fluxer in a business context, as Fluxer is making a point of having data privacy features, like the ability to delete your account and all messages that it has ever sent, and these features are always enabled, for all users, on all instances. This would remain true, and unaffected by the presence or absence of editing and deletion permissions, unless Fluxer goes back on this, and makes those features optional, which I believe would significantly ease abuse on a federated network. I don't think the good outweighs the bad here, and being reductive about the bad won't help. You do not have my support.