Curriculum Portal is a free, open-source web application designed to help schools design their schemes and assessments, and to assign students retrieval practice homeworks.
Deploy effortlessly to Microsoft Azure.
-
Create a general purpose v2 storage account in Microsoft Azure, and within it create:
- Blob containers:
cache,configandcurriculum - Tables:
courses,unitsandxpledger
- Blob containers:
-
Within the
configblob container:-
Upload a blank file
keys.xml. Generate a SAS URL for this file with read/write permissions and a distant expiry. This will be used to store the application's data protection keys so that auth cookies persist across app restarts. -
Upload a file
students.csvwith the following headers and populate it with all students in your school. "Id" can be any unique integer identifier, unless you are using Bromcom to record behaviour events, in which case it must be the Bromcom student ID. "PupilPremium" should betrueorfalsefor each student. The "Classes" field should contain a comma-separated list of classes, wrapped in double quotes. To correctly represent accented characters in student names, save the file in 'CSV UTF-8' format.Id,Email,FirstName,LastName,TutorGroup,PupilPremium,Classes
-
Upload a file
teachers.csvwith the following headers.Id,Email,FirstName,LastName,Classes
-
Upload a file
seniorleaders.csvwith the following header and one email address per row. Senior leaders can edit any course.Email -
Upload a file
holidays.csvwith the following headers and dates inyyyy-MM-ddformat. If an assignment due date lands within a holiday range, it will be pushed forward.Start,End
-
Upload
exemptions.csvwith the following header and one user ID per row for students who should not receive the negative Class Charts behaviour for incomplete homework. If there are no exemptions, this file can be left blank.UserId -
If you are using Class Charts to record behaviour events, upload
classcharts-behaviours.jsoncontaining the behaviour settings for KS3 aggregate homework and each KS4-5 subject code that should receive points. KS4-5 subjects without an entry are skipped.{ "KS3": { "positive": { "id": 100001, "reason": "Revision Quizzes Completed", "score": 10, "icon": "good/+thinking_skills.png" }, "negative": { "id": 100002, "reason": "No Homework - Revision Quizzes Incomplete", "score": -6, "icon": "bad/-lack_of_books.png" } }, "Hi": { "positive": { "id": 100003, "reason": "History Quiz Completed", "score": 6, "icon": "good/+thinking_skills.png" }, "negative": { "id": 100004, "reason": "No Homework - History Quiz Incomplete", "score": -6, "icon": "bad/-lack_of_books.png" } } } -
If you are using Bromcom to record behaviour events, upload
bromcom-behaviours.jsoncontaining the staff owner and one positive and one negative behaviour event type. Bromcom uses these same two event types for all subjects.{ "staffId": 12345, "positive": { "eventTypeId": 100001, "points": 10 }, "negative": { "eventTypeId": 100002, "points": -6 } } -
Upload
checklist.jsoncontaining the checklist items to show for each unit. Eachidmust be unique and may only contain letters, numbers, hyphens, and underscores. On/courses/audit, incomplete items withrequired: truehave a red cross;required: falseor an omittedrequiredhas a grey cross.[ { "id": "participation", "title": "Every lesson includes high-participation activities throughout", "required": true }, { "id": "vocabulary", "title": "Tier 3 vocabulary is identified and explicitly taught", "required": false } ] -
Upload
school-logo.png. -
Upload
school-logo-navbar.png.
-
-
If you are using Microsoft Foundry, create a project and deploy an OpenAI reasoning model (e.g.
gpt-5.6-sol). SetMicrosoftFoundryEndpointto use Microsoft Foundry. IfMicrosoftFoundryEndpointis not set, the app uses the direct OpenAI API instead. -
Create an Azure app registration.
- Name -
Curriculum Portal - Redirect URIs -
https://<app-website-domain>/signin-oidcandhttps://<app-website-domain>/serviceaccount - Implicit grant - ID tokens
- Supported account types - Accounts in this organizational directory only
- API permissions -
Microsoft Graph - User.Readand delegatedMicrosoft Graph - Mail.Send - Token configuration - add an optional claim of type ID:
upn - Certificates & secrets - create a new client secret
- Name -
-
Create an Azure App Service web app.
- Publish mode - Container
- Operating system - Linux
- Image source - Other container registries
- Container name -
main - Access type - Public
- Registry server URL -
https://index.docker.io - Image and tag -
jamesgurung/curriculum-portal:latest - Port - 8080
- Startup command: (blank)
-
Configure the application settings as described below.
If you wish to load settings from Azure App Configuration, specify one of the following:
AppConfigurationEndpoint- Azure App Configuration endpoint. Enable the App Service's system-assigned managed identity and grant it the App Configuration Data Reader role.ConnectionStrings:AppConfiguration- Azure App Configuration connection string.
The remaining application settings are loaded from the
Shared:*andCurriculumPortal:*keys in Azure App Configuration, or from your local configuration:AdminEmails- the email addresses of the admin users who have full administrative access (comma-separated list)AssignmentCompletionHighThreshold- the integer percentage completion rate above which students due assignments today receive the positive behaviour event (set this above100to disable positive behaviours)AssignmentCompletionLowThreshold- the integer percentage completion rate below which students due assignments today receive the negative behaviour event (set this below0to disable negative behaviours)BrandAccentColour- the CSS colour used for the navbar bottom borderBrandColour- the CSS colour used for the navbar backgroundBromcomApplicationId- the Bromcom application ID used to issue behaviours (if you are using Bromcom to record behaviour events)BromcomApplicationSecret- the Bromcom application secret used to issue behaviours (if you are using Bromcom to record behaviour events)BromcomSchoolId- the Bromcom school ID used to issue behaviours (if you are using Bromcom to record behaviour events)ClassChartsEmail- the email address of the Class Charts account used to issue behaviours (if you are using Class Charts to record behaviour events)ClassChartsPassword- the password for the Class Charts account used to issue behaviours (if you are using Class Charts to record behaviour events)DailyTokenLimit- the maximum number of OpenAI tokens to use per UTC day (optional)DataControllerName- the name of the organisation acting as data controller for the privacy pageDataProtectionBlobUri- the SAS URL for the keys file you created earlierMicrosoftClientId- the client ID of your Azure app registrationMicrosoftClientSecret- the client secret of your Azure app registrationMicrosoftFoundryEndpoint- the endpoint URL for your Microsoft Foundry deployment, e.g.https://<project>.cognitiveservices.azure.com/(optional; if set, this is used instead of the OpenAI API)MicrosoftSharePointSubdomain- your Microsoft 365 SharePoint subdomain (for examplecontosoinhttps://contoso.sharepoint.com)MicrosoftTeamsPrefix- theexternalNameprefix used to identify the relevant Microsoft Teams classes when publishing assignment tasks.MicrosoftTenantId- your Azure tenant IDOpenAIAdminApiKey- an OpenAI admin API key used to check daily token usage whenDailyTokenLimitis setOpenAIApiKey- your OpenAI or Microsoft Foundry API keyOpenAIModel- the OpenAI model name or Microsoft Foundry deployment namePrivacyNoticeUrl- the absolute URL of the school's official privacy noticeSchoolName- the name of your schoolStorageAccountConnectionString- the connection string for the Azure Storage accountSyncApiKey- the secret key to use if you update thestudents.csvandteachers.csvfiles with an automated script (optional)Website- the public base URL of your deployed Curriculum Portal, e.g.https://example.com
Configure exactly one behaviour recording provider. If all Bromcom settings are present the app uses Bromcom; if both Class Charts settings are present the app uses Class Charts; if neither provider is configured no behaviour events are recorded. Partial provider settings, or configuring both providers, causes startup to fail.
-
Sign in as an admin and visit
/serviceaccountto authenticate the Microsoft mailbox used for HTML email sending. Note that the service account should not typically be the same as the admin account.
If you have a question or feature request, please open an issue.
To contribute improvements to this project, or to adapt the code for the specific needs of your school, you are welcome to fork the repository.
Pull requests are welcome; please open an issue first to discuss.