Skip to content

LG-10652: A user who is rate limited can password secure account in IDV review step#9024

Merged
amirbey merged 4 commits intomainfrom
amirbey/LG-10652-enqueu-letter-when-rate-limited
Aug 18, 2023
Merged

LG-10652: A user who is rate limited can password secure account in IDV review step#9024
amirbey merged 4 commits intomainfrom
amirbey/LG-10652-enqueu-letter-when-rate-limited

Conversation

@amirbey
Copy link
Contributor

@amirbey amirbey commented Aug 17, 2023

🎫 Ticket

LG-10652

🛠 Summary of changes

Remove rate limit check in review controller. A user can be rate limited for phone entries and select GPO verification.

📜 Testing Plan

Provide a checklist of steps to confirm the changes.

  • Complete IDV steps until /verify/phone is reached (do not complete)
  • Submit invalid phone number repeatedly until rate limited
  • Opt for verify by mail and complete
  • /verify/review is rendered and submit password

changelog: Bug Fixes, Identity Verification, Allow a user rate-limited user to re-enter password on review/Secure your account step"
@amirbey amirbey self-assigned this Aug 17, 2023
@amirbey amirbey changed the title do not enforce idv rate limiter on review controller LG-10652: Rate limited user can complete review step Aug 17, 2023
@amirbey amirbey changed the title LG-10652: Rate limited user can complete review step LG-10652: A user who is rate limited can password secure account in IDV review step Aug 17, 2023
@amirbey amirbey marked this pull request as ready for review August 17, 2023 18:24
@amirbey amirbey requested a review from a team August 17, 2023 18:24
Copy link
Contributor

@soniaconnolly soniaconnolly left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM! I didn't know about skip_before_action. I like that the new test confirms the analytics.

I tested in main and confirmed the bug, then switched to this branch and confirmed I was able to continue and reenter my password.

@amirbey amirbey merged commit 5be3258 into main Aug 18, 2023
@amirbey amirbey deleted the amirbey/LG-10652-enqueu-letter-when-rate-limited branch August 18, 2023 13:33
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants