RocketChat / RocketChat/Rocket.Chat

Bug Report: Update your Integration documentation to show users how to prevent bots from infinitely trigger Outgoing Integrations until it melts down your server as if actual rocket exhaust was launching above it

Open
#23,728 4 comments 4 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Dominant language
TypeScript
Stars
46.1k
Forks
13.9k
Avg merge
3d 3h
Merged PRs (30d)
130

Description

Description:

You might think I'm here to ask a question about why an integration I'm running tries to post to a endpoint that I know works.

Or maybe you're thinking I'd like to know why it not only refuses to post to the endpoint in question, but why the Bot decides to post a blank message to a public channel every time the integration silently fails... and why the integration (which is listening to "all_public_chats") is then reactivated by the bot that is posting a blank message, causing it to loop endlessly until it takes down my server.

You might think I'd be interested in getting an answer to what must surely, by now, be an extremely common occurrence that has been addressed hundreds of times, despite no trace of such solution existing anywhere in the entire searchable universe.

But no. I am not interested in getting a solution to this problem. I am not interested for the same reason there are 2.4k issues. I am not interested for the same reason there are scores of unreplied tickets in the forums.

I'm here to target the SEO of RocketChat. I'm here to make sure that when someone decides to take the plunge on this product, they had better have an entire warehouse of liquor lined up in advance because you, newcomer, are about to experience a product who has been around for so long and has mutated so wildly, even the most basic user-facing features is immune to the most competent Google-fu.

You had better have Russian blackhat cyber forensic murder squads on speed dial before you even THINK about running Rocket.Chat. Anything less than that and you will be knee deep in the codebase of an unsupported version (because some dependency isn't supported on ARM64) whose search popularity and relevance in search engines vanished years ago like the painful memories of virginity given in haste.

You, the delightful little sadist you are, will be consumed by an endless abyss of unanswered issues and a search result set so impenetrable, you can hide NSA secrets in these issues and NO ONE WILL EVER FIND THEM. You have found the internet equivalent of a blackhole. This is the real prime feature of Rocket.Chat.

You've been warned. Rocket.chat is the perfect mixture of feature bloat, data rot, and maturity as obscurity.

Steps to reproduce:
  1. Install RocketChat
  2. Search for any information about why a feature doesn't work
  3. Drink yourself to death
Expected behavior:

Being able to find any useful community support whatsoever.

Actual behavior:

Full-time alcoholism.

Server Setup Information:
  • Version of Rocket.Chat Server: 3.13.8 (Don't ask me to upgrade, you should support ARM64)
  • Operating System: Ubuntu Server 20.04
  • Deployment Method: Snap
  • Number of Running Instances: 1
  • DB Replicaset Oplog: N/A
  • NodeJS Version: v12
  • MongoDB Version: v4
Client Setup Information
  • Desktop App or Browser Version: N/A
  • Operating System: N/A
Additional context

How can a bot even be allowed to endlessly trigger outgoing webhooks that listen to all public chats? Why is the bot even pushing messages to a fucking chat room? Are you out of your mind?

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Start by locating the Integration documentation referenced in the issue and review whether it explains outgoing integrations listening to all public chats and bot-triggered loops. Document the relevant prevention and behavior described by the report, then verify that the resulting guidance addresses the reported failure scenario.

Written by the indexing model from the issue text.

Assessment

Domain
documentation
Issue type
Documentation
Difficulty
4/5
Estimated time
3-5 days
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
15/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.