PAC-K001 · es2015-syntax

ES2015+ syntax (let, const, arrow functions, template literals)

high · Compatibility across engines

Modern browsers accept ES2015 syntax, but PAC files also run in WinHTTP-based clients (Windows services, Edge IE mode, many agents) whose engine is ES5-level or older. There the entire file is a syntax error and all traffic goes DIRECT.

Why it matters

A PAC is parsed by whatever JavaScript engine the consuming client embeds. Chromium (V8) and Firefox (SpiderMonkey) accept current ECMAScript. WinHTTP and the legacy Windows resolver use an older JScript-class engine; const, let, => or back-tick strings are parse errors there, which means mechanism (b) of the silent-DIRECT family for every WinHTTP consumer on the network: Windows Update, Office components, line-of-business services and anything that uses the system proxy via WinHTTP. Older pacparser builds and embedded engines in appliances are equally affected. Nothing in a PAC needs ES2015; var and function declarations express everything.

The grade cap reflects that a file which does not parse on a mainstream client is not merely a style issue. Whether WinHTTP is in scope for a given deployment is an owner decision; see the report.

How to fix

Use var instead of let/const, function expressions instead of arrows, and string concatenation instead of template literals.

Examples

Bad

const PROXY_A = "PROXY proxy.corp.example:8080";
const isCorp = (h) => dnsDomainIs(h, ".corp.example");
function FindProxyForURL(url, host) {
  if (isCorp(host)) {
    return `DIRECT`;
  }
  return PROXY_A;
}
Open bad example in checker

Good

var PROXY_A = "PROXY proxy.corp.example:8080";
function isCorp(h) {
  return dnsDomainIs(h, ".corp.example");
}
function FindProxyForURL(url, host) {
  if (isCorp(host)) {
    return "DIRECT";
  }
  return PROXY_A;
}
Open good example in checker

Engine behaviour

EngineBehaviourSource
chromiumV8; current ECMAScript syntax parses.code, verified 2026-10-04 · ref
firefoxSpiderMonkey; current ECMAScript syntax parses.expert, unverified
pacparserDepends on the bundled SpiderMonkey version; older builds reject ES2015 syntax.expert, unverified
winhttpReported ES5-level engine; ES2015 syntax is a parse error for the whole file.expert, unverified

Source: code = read in the engine's source, doc = vendor documentation, lab = observed in a lab run, expert = practitioner knowledge, not yet verified.

Related rules

References