05c2da2d0f
## Summary - Replace regex-based private IP detection in `isPrivateIp` with Node.js `net.BlockList` for CIDR-based range checking, which properly handles all IPv4-mapped IPv6 representations (both dotted-decimal and hex forms) - Add missing non-routable IP ranges: carrier-grade NAT (`100.64.0.0/10`), IANA special purpose, documentation networks, benchmarking, multicast, and reserved ranges - Add protocol allowlist (http/https only) as an axios request interceptor in `SecureHttpClientService` and as a Zod refinement in the HTTP tool schema ## Test plan - [x] All 100 existing + new tests pass across 4 secure-http-client test suites - [x] New tests cover carrier-grade NAT range boundaries (100.64.0.0 – 100.127.255.255) - [x] New tests cover documentation, benchmarking, multicast, and reserved ranges - [x] New tests cover hex-form IPv4-mapped IPv6 addresses (the form Node.js URL parser actually produces) - [x] New tests verify protocol interceptor blocks `ftp:` and `file:` schemes - [x] New tests verify protocol interceptor is only active when safe mode is enabled Made with [Cursor](https://cursor.com)