alert() used in the PAC
medium
alert() is the PAC specification's debugging hook. Chromium records it internally, Firefox writes to its console, and engines without alert throw, which aborts the evaluation. It has no place in a deployed file.
Why it matters
alert() was defined by the original Netscape PAC environment as a debugging function. It
never shows a dialog in any current browser. Chromium binds it and forwards the message to
its network log (not visible to users; code, 2026-10-04); Firefox logs to the browser
console; WinHTTP is reported not to define it at all, in which case the call throws a
ReferenceError and the request is treated as a script failure. A deployed PAC with
alert() therefore does nothing useful on two engines and may break routing on a third.
Lab verification of the Firefox and WinHTTP behaviour is pending.
How to fix
Remove alert() calls; test PACs with an external evaluator instead.
Examples
Bad
function FindProxyForURL(url, host) {
alert("debug " + host);
return "DIRECT";
}
Open bad example in checkerEngine behaviour
| Engine | Behaviour | Source |
|---|---|---|
| chromium | alert is bound (AlertCallback) and the message is forwarded to the resolver bindings, which record it in the network log; no dialog, no exception. | code, verified 2026-10-04 · ref |
| firefox | Message is written to the browser console; no dialog. | expert, unverified |
| pacparser | Message is passed to the host application's alert handler (pactester prints it). | expert, unverified |
| winhttp | Reported as not defined; the call would throw. | expert, unverified |
Related rules
- console.log or other browser APIs used in the PAC PAC-E018
- Call to a function that is not defined PAC-E005