The _message_post_helper() method historically allowed
passing a `sha_in` signature to let an unauthenticated
user post a message on a record.
This option is unused and an alternative is preferred:
passing a `token` value that matches the value of a
given field of the record.
In light of the increasingly grim future of SHA-1
as a cryptographic hash function, we consider it
better to entirely remove this specific option.
It has been unused for a while, and a simple
alternative exists.
The `object_shasign` method itself will be dropped
in master.