eval or Function constructor in the PAC
medium
eval() or new Function() builds code from strings at runtime. There is no legitimate need for it in a PAC; it hides logic from review and from static analysis.
Why it matters
A PAC is reviewed as text; eval defeats that review because the executed code is only
known at runtime. It also removes the guarantees a static check can give (no undefined
functions, a reachable default return) and is a classic place for obfuscated logic. Some
engines may restrict it. Every routing decision can be expressed with the PAC helpers and
plain conditions.
How to fix
Replace the dynamic code with plain conditions and literals.
Examples
Bad
function FindProxyForURL(url, host) {
var rule = "shExpMatch(host, '*.corp.example')";
if (eval(rule)) {
return "DIRECT";
}
return "PROXY proxy.corp.example:8080";
}
Open bad example in checkerGood
function FindProxyForURL(url, host) {
if (shExpMatch(host, "*.corp.example")) {
return "DIRECT";
}
return "PROXY proxy.corp.example:8080";
}
Open good example in checker