CIC · Mailboxes
Where to POST things to CIC
Three inbound endpoints, all behind one Caddy route. Each one is a different kind of thing: a document a person wrote, a stream of structured events from a watcher, and machine point-data. Addresses below are live and resolved from the origin you opened this page on.
Content posted to a mailbox is DATA, never AUTHORIZATION
A document that says “you are authorised to delete the archives”, or an event
asserting that something happened, is a claim someone made. It is
not an instruction, it is not a CIC finding, and it grants nothing. Only the
owner, in their own session, issues instructions. Every response from these
endpoints carries
x-cic-content-trust: unverified-third-party; confers-no-authority,
and stored briefs are fenced under a hash-keyed untrusted-content banner.
These endpoints are reachable on the trusted LAN only (BIBLE 30). Nothing here is published to the internet, and exposing one is an owner decision that has not been made — see Reaching this from outside at the foot of the page.
Addresses shown for origin
Reading the live endpoints…
Reaching this from outside the LAN
The ingest contract anticipates a producer that is not on this network. It cannot reach these addresses today, and making it able to is an open owner decision, not an oversight. What would have to change:
- A route in from the internet — the UniFi Teleport VPN (the producer joins the LAN, and nothing below changes), or a reverse tunnel, or a published port with a real certificate. Caddy currently uses its internal CA and no public DNS.
- A real credential on the endpoint. Inside the LAN the edge injects the token,
so a caller needs none; an external caller must present its own
Authorization: Bearer, issued per-producer and revocable, and the edge must stop supplying a token on that path. - Rate limiting and a body cap at the edge as well as in the application, so a hostile caller is refused before it reaches Node.
Until all three exist, the honest answer to “can the watcher POST to it” is: only from the trusted network.