Added
- Added
ssrf.allowRangesconfig to exempt CIDR ranges (e.g.198.18.0.0/15) from the SSRF guard, sofetch_content/web_searchwork on hosts whose network proxy runs in TUN + fake-IP mode (Surge, Clash, Mihomo, Stash, ...) where public domains resolve into a synthetic reserved range. Off by default. Thanks @TianZuo555 for reporting #101 and PR #102.
Fixed
- Hardened
ssrf.allowRangesvalidation to reject all-address/0CIDRs and non-string entries.