{"version":"2.1.281","anchor":"egress-allowlist-grammar-and-host-placeholder-strings","canonical_anchor":"egress-allowlist-grammar-and-host-placeholder-strings","heading":"Egress allowlist grammar and host placeholder strings","tier":null,"area":null,"url":"https:\/\/changelogs.core-directive.com\/v\/2.1.281\/e\/egress-allowlist-grammar-and-host-placeholder-strings","release_url":"https:\/\/changelogs.core-directive.com\/v\/2.1.281","markdown":"### Egress allowlist grammar and host placeholder strings\n\nSettings screens gain text describing allowed outbound-host entries and a host-list placeholder; a helper cache TTL field is tagged with a version\n\n**Unclear.** The finding does not say which settings screen shows these strings or what the helper cache TTL field controls.\n\n**What**\n\nNew text was added to the settings interface for the egress allowlist. \"Egress\" means outgoing network connections, and the allowlist is the list of hosts those connections may go to. The text sets out what one entry may look like:\n\n- `*` matches any host, with no port allowed on the bare `*`\n\n- `localhost` names the local machine\n\n- `host[:port]` is a single host, optionally with a port from 1 to 65535\n\n- `*.host[:port]` matches every subdomain of a host, optionally with a port\n\nAn entry may not contain a scheme (such as `https:\/\/`), a path, or an IPv6 literal address. The host-list box shows `*.corp.example.com` as a placeholder example. Separately, a helper cache TTL field (TTL means how long a cached value is kept) is now tagged `availableInVersion 1.19367.0`.\n\n**Why**\n\nAnyone filling in the allowlist now sees the accepted formats spelled out, which helps avoid entries that would not be accepted."}