Skip to content

Tweak the user account data remediation migration

Adam Hegyi requested to merge 220756-tweak-unconfirmation-process into master

What does this MR do?

Addresses the first two points of https://gitlab.com/gitlab-org/gitlab/-/issues/220756#note_377459554

This MR is part of https://gitlab.com/gitlab-org/gitlab/-/issues/220756 where we unconfirmed large volume of users as part of the data remediation process after a security issue fix.

The migration was already executed on GL.com, so these changes will only affect self-hosted.

  • Unset unconfirmed_email field to prevent sending the confirmation email to the wrong address.
  • Add a slight delay when sending the confirmation instructions so the notification email will show up first.

Screenshots

Does this MR meet the acceptance criteria?

Conformity

Availability and Testing

Security

If this MR contains changes to processing or storing of credentials or tokens, authorization and authentication methods and other items described in the security review guidelines:

  • Label as security and @ mention @gitlab-com/gl-security/appsec
  • The MR includes necessary changes to maintain consistency between UI, API, email, or other methods
  • Security reports checked/validated by a reviewer from the AppSec team

Closes #220756

Edited by Adam Hegyi

Merge request reports