Require B2B data consent on the contract dashboard - #4006
Merged
Merged
Conversation
OpenAPI ChangesNo changes detected Unexpected changes? Ensure your branch is up-to-date with |
Contributor
There was a problem hiding this comment.
Copilot review overview
🟡 Changes recommended
The dashboard remains actionable while the consent feature flag is unresolved, creating a consent-bypass window.
Review effort: Balanced
Findings: 1
Open (1)
What changed in this PR
Adds feature-flagged B2B learner-data consent to contract dashboards.
Changes:
- Adds a mandatory consent dialog and API mutation.
- Disables course actions until consent is granted while preserving certificate links.
- Updates MITx Online types, factories, dependencies, and tests.
| File | Description |
|---|---|
yarn.lock |
Locks the updated MITx Online client. |
frontends/ol-components/src/components/Dialog/Dialog.tsx |
Supports hiding the close button. |
frontends/main/src/common/feature_flags.ts |
Registers the consent flag. |
frontends/main/src/app-pages/DashboardPage/DataConsentDialog.tsx |
Implements the consent dialog. |
frontends/main/src/app-pages/DashboardPage/DataConsentDialog.test.tsx |
Tests dialog behavior. |
frontends/main/src/app-pages/DashboardPage/DashboardLayout.test.tsx |
Updates organization types. |
frontends/main/src/app-pages/DashboardPage/CoursewareDisplay/UnenrolledCourseCard.tsx |
Supports disabled unenrolled cards. |
frontends/main/src/app-pages/DashboardPage/CoursewareDisplay/UnenrolledCourseCard.test.tsx |
Tests disabled unenrolled cards. |
frontends/main/src/app-pages/DashboardPage/CoursewareDisplay/test-utils.ts |
Updates contract fixture types. |
frontends/main/src/app-pages/DashboardPage/CoursewareDisplay/SiblingRunsAccordion.tsx |
Disables run actions. |
frontends/main/src/app-pages/DashboardPage/CoursewareDisplay/OrganizationCards.test.tsx |
Updates organization fixture types. |
frontends/main/src/app-pages/DashboardPage/CoursewareDisplay/EnrolledCourseCard.tsx |
Disables enrolled-card actions. |
frontends/main/src/app-pages/DashboardPage/CoursewareDisplay/EnrolledCourseCard.test.tsx |
Tests disabled enrolled cards. |
frontends/main/src/app-pages/DashboardPage/CoursewareDisplay/CoursewareCard.tsx |
Propagates disabled state. |
frontends/main/src/app-pages/DashboardPage/ContractContent.tsx |
Integrates consent state and mutation. |
frontends/main/src/app-pages/DashboardPage/ContractContent.test.tsx |
Tests consent dashboard flows. |
frontends/main/src/app-pages/DashboardPage/AnalyticsContent.test.tsx |
Updates organization types. |
frontends/main/package.json |
Updates the MITx Online client source. |
frontends/api/src/mitxonline/test-utils/urls.ts |
Adds the consent endpoint URL. |
frontends/api/src/mitxonline/test-utils/factories/organization.ts |
Uses learner organization types. |
frontends/api/src/mitxonline/test-utils/factories/contracts.ts |
Adds consent to contract fixtures. |
frontends/api/src/mitxonline/hooks/organizations/index.ts |
Adds the consent mutation hook. |
frontends/api/package.json |
Updates the MITx Online client source. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
gumaerc
force-pushed
the
cg/data-consent-modal
branch
2 times, most recently
from
September 29, 2026 18:14
f8a28a0 to
4136cdb
Compare
Contributor
Author
|
@zamanafzal The API change has been released and the API package was upgraded, this is officially ready for a full review. |
…onsent Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…setup Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…pi-generator v7.25.0 The previous branch build used v7.2.0, which names some types differently from published releases. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
gumaerc
force-pushed
the
cg/data-consent-modal
branch
from
September 29, 2026 21:11
74b7c08 to
c50e26a
Compare
zamanafzal
approved these changes
Sep 30, 2026
zamanafzal
left a comment
Contributor
There was a problem hiding this comment.
LGTM.
Tested locally against a B2B org with contract and flag on in PostHog.
- Dialog shows on load of the contract dashboard while consent is unset
- Ticked the checkbox and clicked Agree and continue — dialog closes and
does not come back on reload - On decline the dialog returns on the next load
- Flag off in PostHog: no dialog regardless of consent state.
- Until consent is
true, both the enrolled and unenrolled cards stay gated —
CTA disabled.
mbertrand
pushed a commit
that referenced
this pull request
Oct 1, 2026
* chore(api): use the mitxonline-api-axios branch build with contract consent Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * feat(ol-components): let Dialog hide its close button Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * feat(api): add useDataConsentMutation and learner contract factories Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * feat(dashboard): add a disabled state to course cards Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * feat(dashboard): add the B2B data consent dialog behind a feature flag Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * feat(dashboard): require data consent on the B2B contract dashboard Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * test(dashboard): use learner contract and organization types in test setup Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * fix(dashboard): show the consent spinner on the button that was clicked Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * chore(api): rebuild the mitxonline-api-axios branch client with openapi-generator v7.25.0 The previous branch build used v7.2.0, which names some types differently from published releases. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * switch back to published api package --------- Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
mbertrand
pushed a commit
that referenced
this pull request
Oct 1, 2026
* chore(api): use the mitxonline-api-axios branch build with contract consent Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * feat(ol-components): let Dialog hide its close button Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * feat(api): add useDataConsentMutation and learner contract factories Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * feat(dashboard): add a disabled state to course cards Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * feat(dashboard): add the B2B data consent dialog behind a feature flag Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * feat(dashboard): require data consent on the B2B contract dashboard Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * test(dashboard): use learner contract and organization types in test setup Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * fix(dashboard): show the consent spinner on the button that was clicked Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * chore(api): rebuild the mitxonline-api-axios branch client with openapi-generator v7.25.0 The previous branch build used v7.2.0, which names some types differently from published releases. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> * switch back to published api package --------- Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.

What are the relevant tickets?
Closes https://github.com/mitodl/hq/issues/13575
Depends on mitodl/mitxonline#4039
Description (What does it do?)
B2B learners now have to consent to share their learner data with their organization before they can use a contract's dashboard. Everything is behind the
b2b-data-consentPostHog flag.true. The dialog can only be closed with Agree or Decline. Design: https://www.figma.com/design/mSDdN8giMcncBwNgwcVJL9/?node-id=21368-21707true, every card on the page is disabled: disabled CTA and context menu, and a plain-text title. Certificate links keep working.Implementation details
consented_to_data_sharingon the contracts in mitxonline'susers/meand written withPOST /api/v0/b2b/data_consent/<contract_id>/.useDataConsentMutationstays pending untilusers/merefetches, so the dialog closes and the cards enable in the same render.Dialogin ol-components gets ashowCloseButtonprop.CoursewareCardand the enrolled/unenrolled cards get adisabledprop. ContractContent sets it on every card.UserContractPage/UserOrganizationPage), with consent defaulting tonull.Screenshots (if appropriate):
How can this be tested?
Requires mitxonline running mitodl/mitxonline#4039.
b2b-data-consentin PostHog.Checklist:
@mitodl/mitxonline-api-axiosbranch build (GitHub tarball) for the released version once Return the user's data sharing consent on their B2B contracts mitxonline#4039 ships