PAC-C028 · cloudflare-gateway-endpoint-port

Cloudflare Gateway proxy endpoint on a port other than 443

high · Correctness

Every Cloudflare example returns the proxy endpoint with port 443. Another port is not a TLS listener of the endpoint; the browser's connection fails and the request falls through.

Why it matters

Cloudflare’s default template, the identity-provider template and the correct/incorrect pair all use HTTPS <subdomain>.proxy.cloudflare-gateway.com:443. Nothing in the proxy endpoint documentation offers another port. A typo such as :8443 or :80 leaves the browser trying to open TLS to a port that does not answer, with the same outcome as PAC-C027: no proxying, and a direct connection if a DIRECT entry follows.

How to fix

Use port 443 on the Gateway proxy endpoint entry.

Examples

Bad

function FindProxyForURL(url, host) {
  if (isPlainHostName(host)) {
    return "DIRECT";
  }
  return "HTTPS abc123def0.proxy.cloudflare-gateway.com:8443";
}
Open bad example in checker

Good

function FindProxyForURL(url, host) {
  if (isPlainHostName(host)) {
    return "DIRECT";
  }
  return "HTTPS abc123def0.proxy.cloudflare-gateway.com:443";
}
Open good example in checker

Cloudflare pack only.

Related rules

References