Variable
ConstKeys routed to a private store resolve to this path instead of to a bucket
URL, which is what lets BlobStore.url() stay synchronous while signing is
asynchronous. The response is always a redirect — see contentRedirect
for why bytes are never proxied.
Dynamic by construction: a signed URL is time-limited, so this response must never be statically cached.
Signing endpoint for privately-stored course content.