AntiPattern
IP Allowlist Misuse
ip-allowlist-weak-security
IP-range allowlists and client-side checks are treated as effective security controls, but the mechanism is bypassable or overly broad, letting intercepted or replayed requests slip through unless egress IPs are explicitly enumerated and consistently enforced server-side.