Expand compressed IPv6 hostnames before the private-address allowlist so forms like ::1 cannot bypass SSRF protection for WebDAV/S3 backup endpoints. Also reject IPv4-mapped addresses written as ::ffff:hex:hex.