PAC-K010 · es2015-builtins

ES2015+ library methods (includes, startsWith, Map, Set)

medium · Compatibility across engines

Unlike ES2015 syntax, newer library methods parse fine on an old engine and fail only at runtime with a TypeError for the request that reaches them. The branch then behaves like a script failure.

Why it matters

host.endsWith(".corp.example") is a syntax-level ES5 program, so an ES5 engine loads the file and only throws TypeError: host.endsWith is not a function when the line executes. That is harder to notice than a parse error: the PAC works in Chrome and in a quick test, and fails on WinHTTP consumers for exactly the hosts that reach the branch. ES5 equivalents exist for all of them (indexOf, slice, substring, shExpMatch, dnsDomainIs).

How to fix

Use dnsDomainIs/shExpMatch for suffix and prefix tests and indexOf for membership; avoid Map/Set/Promise in PAC files.

Examples

Bad

var direct = ["intranet.corp.example", "wiki.corp.example"];
function FindProxyForURL(url, host) {
  if (direct.includes(host) || host.endsWith(".lab.example")) {
    return "DIRECT";
  }
  return "PROXY proxy.corp.example:8080";
}
Open bad example in checker

Good

var direct = ["intranet.corp.example", "wiki.corp.example"];
function FindProxyForURL(url, host) {
  if (direct.indexOf(host) >= 0 || dnsDomainIs(host, ".lab.example")) {
    return "DIRECT";
  }
  return "PROXY proxy.corp.example:8080";
}
Open good example in checker

Related rules

References