Skip to content

Loopback ?api= override rejects 127.0.0.2 #3407

Description

@ohdearquant

resolveApiOverride accepts only the exact hostnames 127.0.0.1, localhost, and ::1. The CLI treats the entire 127.0.0.0/8 range as loopback, so a daemon launched on 127.0.0.2:8766 cannot be selected with the advertised ?api= override: the parameter is ignored and the page falls back to its baked API base. Validate IP literals semantically as loopback addresses while continuing to reject non-loopback hosts.

The allowlist is here, while the supported 127.0.0.2 loopback behavior is exercised here. This behavior was introduced in PR #3404.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    regression-watchConfirmed regressions in merged changes

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions