console.log or other browser APIs used in the PAC
high
The PAC sandbox is not a web page. console, window, document, fetch, setTimeout and similar objects are not defined; using them throws a ReferenceError and aborts the evaluation.
Why it matters
PAC code runs in a minimal JavaScript context that provides the PAC helpers and the
ECMAScript built-ins only. console.log(host) left over from debugging in a browser’s
developer console throws ReferenceError: console is not defined when the engine runs it,
which has the same effect as any other exception (PAC-E006): the request is handled as a
script failure. The only debugging output function defined by the PAC specification is
alert(), whose behaviour also varies (PAC-K002).
Draft until the exact set of undefined globals per engine has been confirmed in the lab; Chromium’s resolver context is defined by its PAC JavaScript library plus V8 built-ins.
How to fix
Remove console/window/document references; use a test harness outside the PAC for debugging.
Examples
Bad
function FindProxyForURL(url, host) {
console.log("PAC called for " + host);
return "PROXY proxy.corp.example:8080";
}
Open bad example in checkerGood
function FindProxyForURL(url, host) {
return "PROXY proxy.corp.example:8080";
}
Open good example in checkerEngine behaviour
| Engine | Behaviour | Source |
|---|---|---|
| chromium | Resolver context provides only the PAC helpers and ECMAScript built-ins; console is not defined. | expert, unverified |
Related rules
- Call to a function that is not defined PAC-E005
- Evaluation throws an exception PAC-E006
- alert() used in the PAC PAC-K002