Everything below comes from appsettings.json (or environment/user-secrets overrides).
It is shown here so the portal's behaviour is visible without opening a config file.
Voice notes (OpenAI)
Set OpenAI:ApiKey (user-secrets or environment) to enable voice notes on lesson
recaps. Audio is streamed to OpenAI for transcription and discarded; transcripts are stored as
the recap's source notes.
Media storage
Public media URLs are always composed from the CDN base (Front Door), never from
the blob endpoint. Without a CDN base, files are served through the app's
/media route instead.
Application
Used to build links that go out by email. In production this must be the externally reachable address, not localhost.
Admin access
Sign-in is deliberately deferred. Every admin route already carries the
AdminPortal policy, so registering an SSO scheme and setting
Admin:RequireAuth to true locks the portal down without
any code change. Until then, protect this deployment at the network level.