This is a [Next.js](https://nextjs.org) project bootstrapped with [`create-next-app`](https://nextjs.org/docs/app/api-reference/cli/create-next-app).

## Getting Started

First, run the development server:

```bash
npm run dev
# or
yarn dev
# or
pnpm dev
# or
bun dev
```

Open [http://localhost:3000](http://localhost:3000) with your browser to see the result.

## Transactional email (Brevo SMTP)

All application email is sent through Brevo SMTP with `nodemailer`. Configure
these server-only environment variables:

```bash
BREVO_SMTP_HOST=smtp-relay.brevo.com
BREVO_SMTP_PORT=587
BREVO_SMTP_USER=your-brevo-smtp-login
BREVO_SMTP_PASS=your-brevo-smtp-key
MAIL_FROM_EMAIL=noreply@in.cambridgeveritas.com
MAIL_FROM_NAME="Cambridge Veritas"
OTP_FROM_EMAIL=otp@in.cambridgeveritas.com
MAIL_REPLY_TO=contact@cambridgeveritas.com
```

`MAIL_FROM` remains supported as a legacy sender fallback. OTP emails use
`OTP_FROM_EMAIL` when it is configured; all other messages use
`MAIL_FROM_EMAIL`. Never add a `NEXT_PUBLIC_` prefix to email credentials.

## Registration security

Password registration uses Cloudflare Turnstile followed by a six-digit email
OTP. Configure these environment variables in production:

```bash
NEXT_PUBLIC_TURNSTILE_SITE_KEY=
TURNSTILE_SECRET_KEY=
TURNSTILE_ALLOWED_HOSTNAMES=cambridgeveritas.com,www.cambridgeveritas.com
EMAIL_OTP_SECRET=
EMAIL_OTP_EXPIRY_MINUTES=10
EMAIL_OTP_RESEND_COOLDOWN_SECONDS=60
EMAIL_OTP_MAX_ATTEMPTS=5
REGISTRATION_OTP_EMAIL_TEMPLATE=otp
```

The Turnstile secret and OTP secret are server-only and must never use a
`NEXT_PUBLIC_` prefix. Development falls back to Cloudflare's official test
keys. Run `scripts/migrations/20260825_registration_security.sql` before
deploying the registration flow to an existing database.

## Zoho CRM

Contact-us enquiries are saved to the `contact_enquiries` MySQL table before
being upserted into the Zoho CRM `Leads` module. Configure these server-only
environment variables:

```bash
ZOHO_CRM_ENABLED=true
ZOHO_REFRESH_TOKEN=
ZOHO_CLIENT_ID=
ZOHO_CLIENT_SECRET=
ZOHO_ACCOUNTS_BASE_URL=https://accounts.zoho.in
ZOHO_CRM_BASE_URL=https://www.zohoapis.in/crm/v7
ZOHO_CRM_MODULE=Leads
```

The contact form maps `First_Name`, `Last_Name`, `Phone`, `Email`, and
`Description`, with `Lead_Source=Website` and `Lead_Type=Contact`. Zoho
credentials must never use a `NEXT_PUBLIC_` prefix.

CVAT, CVTE, and CVIM introduction-class registrations are also saved to their
MySQL registration table before Zoho is called. They use `Lead_Source=Website`
and the matching `Lead_Type` (`Introduction class CVAT`, `Introduction class
CVTE`, or `Introduction class CVIM`). Run
`scripts/migrations/20260727_intro_class_zoho_sync.sql` once on an existing
database; the application also adds the sync-tracking columns defensively when
an introduction-class registration is submitted.

The same Lead is upserted again after introduction-class attendance,
rescheduling, or cancellation. `Attendance` is stored as `0` for a current
booking, `1` after joining, and `Cancelled` after cancellation. Rescheduling
also replaces the webinar ID, session date/time, and attendee URLs in Zoho.

All course level-test submissions are saved to `level_test_result` before the
Zoho upsert and use `Lead_Source=Website` with `Lead_Type=Level test`. The CRM
ID and delivery result are retained in the existing `crmid` and `response`
columns.

VNA Professionals partnership enquiries are saved to
`vna_partnership_enquiries` before Zoho is called. They use
`Lead_Source=Website` and `Lead_Type=Vnaprofessionals`, together with the
institution, role, country, estimated students, preferred call time, and
placement challenges. Run
`scripts/migrations/20260727_vna_professionals_zoho_sync.sql` on an existing
database; the submission route also creates missing sync columns defensively.

## Speech analyzer Python dependencies

Pitch, pace, pause, and hesitation analysis runs in Python. Install and verify
its dependencies with the same operating-system account that runs the Next.js
service:

```bash
npm run speech:python-deps
npm run speech:python-deps:check
```

The installer and the application both prefer `python3` on Linux and `python`
on Windows. To use a virtual environment in production, create it once and set
`SPEECHSUPER_PYTHON_BINARY` in the service environment before installing:

```bash
cd /var/www/html
python3 -m venv .venv
SPEECHSUPER_PYTHON_BINARY=/var/www/html/.venv/bin/python npm run speech:python-deps
```

Keep `SPEECHSUPER_PYTHON_BINARY=/var/www/html/.venv/bin/python` configured for
the running Next.js service, and restart the service after installation.

Automatic speech-result prompt analysis uses OpenAI exclusively. Configure
`OPENAI_API_KEY` and, optionally, `OPENAI_MODEL`; credentials for other AI
providers are not used when generating user speech results.

You can start editing the page by modifying `app/page.tsx`. The page auto-updates as you edit the file.

This project uses [`next/font`](https://nextjs.org/docs/app/building-your-application/optimizing/fonts) to automatically optimize and load [Geist](https://vercel.com/font), a new font family for Vercel.

## Learn More

To learn more about Next.js, take a look at the following resources:

- [Next.js Documentation](https://nextjs.org/docs) - learn about Next.js features and API.
- [Learn Next.js](https://nextjs.org/learn) - an interactive Next.js tutorial.

You can check out [the Next.js GitHub repository](https://github.com/vercel/next.js) - your feedback and contributions are welcome!

## Deploy on Vercel

The easiest way to deploy your Next.js app is to use the [Vercel Platform](https://vercel.com/new?utm_medium=default-template&filter=next.js&utm_source=create-next-app&utm_campaign=create-next-app-readme) from the creators of Next.js.

Check out our [Next.js deployment documentation](https://nextjs.org/docs/app/building-your-application/deploying) for more details.
