PAC-K002 · alert-in-pac

alert() used in the PAC

medium · Compatibility across engines

alert() is the PAC specification's debugging hook. Chromium records it internally, Firefox writes to its console, and engines without alert throw, which aborts the evaluation. It has no place in a deployed file.

Why it matters

alert() was defined by the original Netscape PAC environment as a debugging function. It never shows a dialog in any current browser. Chromium binds it and forwards the message to its network log (not visible to users; code, 2026-10-04); Firefox logs to the browser console; WinHTTP is reported not to define it at all, in which case the call throws a ReferenceError and the request is treated as a script failure. A deployed PAC with alert() therefore does nothing useful on two engines and may break routing on a third. Lab verification of the Firefox and WinHTTP behaviour is pending.

How to fix

Remove alert() calls; test PACs with an external evaluator instead.

Examples

Bad

function FindProxyForURL(url, host) {
  alert("debug " + host);
  return "DIRECT";
}
Open bad example in checker

Good

function FindProxyForURL(url, host) {
  return "DIRECT";
}
Open good example in checker

Engine behaviour

EngineBehaviourSource
chromiumalert is bound (AlertCallback) and the message is forwarded to the resolver bindings, which record it in the network log; no dialog, no exception.code, verified 2026-10-04 · ref
firefoxMessage is written to the browser console; no dialog.expert, unverified
pacparserMessage is passed to the host application's alert handler (pactester prints it).expert, unverified
winhttpReported as not defined; the call would throw.expert, unverified

Source: code = read in the engine's source, doc = vendor documentation, lab = observed in a lab run, expert = practitioner knowledge, not yet verified.

Related rules

References