@jf as a "security feature" actually. In case you had your internal mastodon processes on an external IP for whatever unholy reason, spoofing 127.0.0.1 would allow you to brute force passwords and more fun stuff. So nothing that even remotely impacted us.