Skip to content
GitLab
Next
Projects Groups Snippets
  • /
  • Help
    • Help
    • Support
    • Community forum
    • Submit feedback
    • Contribute to GitLab
  • Sign in / Register
  • GitLab GitLab
  • Project information
    • Project information
    • Activity
    • Labels
    • Members
  • Repository
    • Repository
    • Files
    • Commits
    • Branches
    • Tags
    • Contributors
    • Graph
    • Compare
    • Locked Files
  • Issues 44,761
    • Issues 44,761
    • List
    • Boards
    • Service Desk
    • Milestones
    • Iterations
    • Requirements
  • Merge requests 1,329
    • Merge requests 1,329
  • CI/CD
    • CI/CD
    • Pipelines
    • Jobs
    • Schedules
    • Test Cases
  • Deployments
    • Deployments
    • Environments
    • Releases
  • Packages and registries
    • Packages and registries
    • Package Registry
    • Container Registry
    • Infrastructure Registry
  • Monitor
    • Monitor
    • Metrics
    • Incidents
  • Analytics
    • Analytics
    • Value stream
    • CI/CD
    • Code review
    • Insights
    • Issue
    • Repository
  • Snippets
    • Snippets
  • Activity
  • Graph
  • Create a new issue
  • Jobs
  • Commits
  • Issue Boards
Collapse sidebar
  • GitLab.orgGitLab.org
  • GitLabGitLab
  • Issues
  • #30327
Closed
Open
Issue created Jul 22, 2019 by Cindy Pallares 🦉@cindy⭐Developer

Auto responder spamming issues and comments in gitlab-org group

Summary

A user who had a Watch setting for the gitlab-org group and had a email set with an auto-responder to say the person was no longer part of the company. Every e-mail notification from a project inside gitlab-org would trigger the auto-responder and would successfully post comments with the auto-responder message.

Disabling the watch setting stopped the emails.

Example comments

https://gitlab.com/gitlab-org/gitlab-ee/merge_requests/14597#note_194460436

What is the current bug behavior?

Auto-response emails were not rejected.

Possible fixes

As Stan mentioned:

Ideally we should quarantine or stop these auto-responders because anyone could easily do this and overwhelm our issues.

We need to inspect the headers for these replies. Perhaps we need to update the headers that are marked as auto-generated emails.

Edited Jul 22, 2019 by Cindy Pallares 🦉
Assignee
Assign to
Time tracking