Feature #484158, the IP allow/deny host authentication code has now been completed and commited. It's been in live testing on my public server for a week now, using cookie authentication mode. I would appreciate some more testing of the code, particularlly under the HTTP and Config authentication modes.
I'm still working on the DB-Config stuff. More to follow on that later.