resolveApiOverride accepts only the exact hostnames 127.0.0.1, localhost, and ::1. The CLI treats the entire 127.0.0.0/8 range as loopback, so a daemon launched on 127.0.0.2:8766 cannot be selected with the advertised ?api= override: the parameter is ignored and the page falls back to its baked API base. Validate IP literals semantically as loopback addresses while continuing to reject non-loopback hosts.
The allowlist is here, while the supported 127.0.0.2 loopback behavior is exercised here. This behavior was introduced in PR #3404.
resolveApiOverrideaccepts only the exact hostnames127.0.0.1,localhost, and::1. The CLI treats the entire127.0.0.0/8range as loopback, so a daemon launched on127.0.0.2:8766cannot be selected with the advertised?api=override: the parameter is ignored and the page falls back to its baked API base. Validate IP literals semantically as loopback addresses while continuing to reject non-loopback hosts.The allowlist is here, while the supported
127.0.0.2loopback behavior is exercised here. This behavior was introduced in PR #3404.