PAC-X015 · dynamic-code-evaluation

eval or Function constructor in the PAC

medium · Security and fail-safety

eval() or new Function() builds code from strings at runtime. There is no legitimate need for it in a PAC; it hides logic from review and from static analysis.

Why it matters

A PAC is reviewed as text; eval defeats that review because the executed code is only known at runtime. It also removes the guarantees a static check can give (no undefined functions, a reachable default return) and is a classic place for obfuscated logic. Some engines may restrict it. Every routing decision can be expressed with the PAC helpers and plain conditions.

How to fix

Replace the dynamic code with plain conditions and literals.

Examples

Bad

function FindProxyForURL(url, host) {
  var rule = "shExpMatch(host, '*.corp.example')";
  if (eval(rule)) {
    return "DIRECT";
  }
  return "PROXY proxy.corp.example:8080";
}
Open bad example in checker

Good

function FindProxyForURL(url, host) {
  if (shExpMatch(host, "*.corp.example")) {
    return "DIRECT";
  }
  return "PROXY proxy.corp.example:8080";
}
Open good example in checker

Related rules

References