Skip to content

redirect ridp verified consumers on pre ridp pages#6124

Open
mdkaraman wants to merge 5 commits intotrunkfrom
868j0am0q_consumer_roles_controller_fixes
Open

redirect ridp verified consumers on pre ridp pages#6124
mdkaraman wants to merge 5 commits intotrunkfrom
868j0am0q_consumer_roles_controller_fixes

Conversation

@mdkaraman
Copy link
Copy Markdown
Contributor

@mdkaraman mdkaraman commented Mar 25, 2026

PR Checklist

Please check if your PR fulfills the following requirements:

  • The title follows our guidelines
  • Tests for the changes have been added (for bug fixes/features), and they use let helpers and before blocks.
  • For all UI changes, there is Cucumber coverage.
  • Any endpoint touched in the PR has an appropriate Pundit policy. For open endpoints, the reasoning is documented in the PR and code.
  • Any endpoint modified in the PR only responds to the expected MIME types.
  • For all scripts or rake tasks, how to run them is documented in both the PR and the code.
  • There are no inline styles added.
  • There is no inline JavaScript added.
  • There is no hard-coded text added/updated in helpers/views/JavaScript. New/updated translation strings do not include markup/styles unless there is supporting documentation.
  • Code does not use .html_safe.
  • All images added/updated have alt text.
  • Does not bypass RuboCop rules in any way.

PR Type

What kind of change does this PR introduce?:

  • Bugfix
  • Feature (requires Feature flag)
  • Data fix, Migration, or Report (inert code, no impact until run)
  • Refactoring (no functional changes, no API changes)
  • Build related changes
  • CI related changes
  • Dependency updates (e.g., add a new gem or update to a version)
  • Release (Prepares code for a release, e.g., version bumps, changelog updates, tagging, deployment scripts)

What is the ticket # detailing the issue?

Ticket: https://app.clickup.com/t/868j0am0q

A brief description of the changes:

Current behavior: consumers who are RIDP verified have access to pages in the pre-RIDP flow (edit Personal Information and Contact Preferences pages). Users with broker or assister roles also technically have access to the edit Personal Information page.

New behavior: consumers who are RIDP verified are redirected to the family home page if they attempt to visit the pre-RIDP flow pages (edit Personal Information and Contact Preferences pages). Users with broker or assister roles are not authorized to visit the edit Personal Information page for consumers (aside from themselves).

Feature Flag

For all new feature development, a feature flag is required to control the exposure of the feature to our end users. A feature flag needs a corresponding environment variable to initialize the state of the flag. Please share the name of the environment variable below that would enable/disable the feature and indicate which client(s) it applies to.

Variable name:

  • DC
  • ME

Additional Context

Motivation for these changes: after QHP (CR-120+) functionality was introduced, the expectation is that edit Personal Information and Contact Preferences pages are only valid to access when user has not yet completed RIDP. Brokers and assisters are not available to consumers before RIDP, so they should not have access to these pages as well (unless they are creating their own consumer account).

@mdkaraman mdkaraman changed the title redirect ridp verified consumers redirect ridp verified consumers on pre ridp pages Mar 25, 2026
@mdkaraman mdkaraman marked this pull request as ready for review March 26, 2026 18:25
@mdkaraman mdkaraman enabled auto-merge (squash) March 26, 2026 20:47
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant