Swap Authenticator to host+IP whitelist

The Authenticator we use has a whitelist. Previously that whitelist was
a list of URLs, which is very suboptimal (and only worked by chance for
attachments). Now we simply observe the host and IP and make sure they
are what we expect.
1 file changed