Currently, the README specifies adding rpcallowip=0.0.0.0 to zcash.conf to work in "regtest mode."
0.0.0.0 can mean different things in different contexts, IIUC, and in some cases it means "any address" ie, any connection is not ruled out. I'm honestly not sure what it means exactly given this context, but it's a question we need to either know well the answer to, and understand it poses no problem in itself, or solve by suggesting something different that also works, before a general launch.