PAC-C009 · apex-without-subdomains

Domain matched exactly, subdomains not covered

low · Correctness

host == "example.com" matches exactly that name. www.example.com, api.example.com and every other subdomain fall through. If the whole site was meant, add the subdomain pattern.

Why it matters

Web properties live on subdomains at least as often as on the apex. A rule for example.com alone is usually a half-rule: the browser loads www.example.com, the rule does not match, and the request takes a different route than the author expects. This is the counterpart of the leading-dot rule (PAC-X003): the safe idiom covers both the apex and its subdomains explicitly. Not flagged when a matching *.domain or .domain pattern exists anywhere in the file.

How to fix

Combine both forms, e.g. host == "example.com" || dnsDomainIs(host, ".example.com").

Examples

Bad

function FindProxyForURL(url, host) {
  if (host == "example.com") {
    return "DIRECT";
  }
  return "PROXY proxy.corp.example:8080";
}
Open bad example in checker

Good

function FindProxyForURL(url, host) {
  if (host == "example.com" || dnsDomainIs(host, ".example.com")) {
    return "DIRECT";
  }
  return "PROXY proxy.corp.example:8080";
}
Open good example in checker

Related rules