Jonathan KirkwoodandClaude Fable 5 0822eca887 0.2.38: optional two-factor authentication (authenticator-app TOTP)
Per-user opt-in 2FA: enroll from the Two-factor option next to Change
password (QR + confirm code + 8 one-time recovery codes), login becomes
two-step for enrolled users, disable requires the account password.
Escape hatch for lost phones: reset-2fa CLI + Reset Two-Factor StartOS
action. Second-factor guesses share the login rate limiter; the pending
login window expires after 5 minutes.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-11 22:08:04 +02:00
2026-06-07 19:23:26 +00:00

Ten31Portal

Internal system of record for Ten31 entities, holdings, positions, and quarterly valuation sign-off.

Accounts and access

Two kinds of accounts:

  • Internal staff (approver, cfo, fund_admin, viewer) — the full back-office app (entities, holdings, valuations, import, audit). approver and cfo also get the admin screens below.
  • External accounts (investor, fund_administrator) — a separate, entity-scoped portal. An external account only sees the entities granted to it.
    • Investor — sees, per fund, their latest capital-account value and history, plus documents shared to the fund or addressed privately to them (e.g. their K-1).
    • Fund administrator — sees assigned entities and can upload documents for them (shared or addressed to a specific investor).

Admin screens (Users / Documents / Capital Accounts, visible to approver and cfo) let you create an account with a username and password, check off which entities it can view, upload documents, and enter each investor's capital-account figures.

Login accepts a username or an email. The first admin is created from the CLI:

ten31portal-cli create-user --name "You" --username admin --role cfo --password '...'
# --email is optional; external accounts are normally created from the Users screen.

Prerequisites

  • Python 3.11+
  • Node.js 20+

Backend

cd backend
python -m venv .venv
source .venv/bin/activate
pip install -e .
uvicorn ten31portal.main:app --reload --port 8000

Health check: GET http://localhost:8000/api/health

Frontend

cd frontend
npm install
npm run dev

Opens at http://localhost:5173. Proxies /api to the backend on port 8000.

Project structure

ten31portal/
  backend/
    ten31portal/       # FastAPI application
      main.py          # App object and health endpoint
      config.py        # Env-based configuration
    pyproject.toml
  frontend/
    src/
      App.tsx          # Main component
      main.tsx         # Entry point
    vite.config.ts
  deploy/              # StartOS packaging (Issue 17)
  SPEC.md              # v1 issue specs
S
Description
mirror of gitea.ten31.ai Ten31AI/Ten31-Portal
Readme MIT
575 KiB
Languages
TypeScript 49.6%
Python 48.2%
Makefile 0.9%
Shell 0.4%
JavaScript 0.4%
Other 0.5%