Admin API remains externally accessible after configuring adminHost for localhost
When securing a Node-RED instance, administrators often set the adminHost property to 127.0.0.1 to limit the HTTP admin API to the loopback interface. The goal is to confirm that this setting alone prevents any external host from reaching the editor UI and deploying flows, while preserving normal flow execution through HTTP input/output nodes. Uncertainty re