ES2015+ syntax (let, const, arrow functions, template literals)
high
Modern browsers accept ES2015 syntax, but PAC files also run in WinHTTP-based clients (Windows services, Edge IE mode, many agents) whose engine is ES5-level or older. There the entire file is a syntax error and all traffic goes DIRECT.
Why it matters
A PAC is parsed by whatever JavaScript engine the consuming client embeds. Chromium (V8)
and Firefox (SpiderMonkey) accept current ECMAScript. WinHTTP and the legacy Windows
resolver use an older JScript-class engine; const, let, => or back-tick strings are
parse errors there, which means mechanism (b) of the silent-DIRECT family for every
WinHTTP consumer on the network: Windows Update, Office components, line-of-business
services and anything that uses the system proxy via WinHTTP. Older pacparser builds and
embedded engines in appliances are equally affected. Nothing in a PAC needs ES2015; var
and function declarations express everything.
The grade cap reflects that a file which does not parse on a mainstream client is not merely a style issue. Whether WinHTTP is in scope for a given deployment is an owner decision; see the report.
How to fix
Use var instead of let/const, function expressions instead of arrows, and string concatenation instead of template literals.
Examples
Bad
const PROXY_A = "PROXY proxy.corp.example:8080";
const isCorp = (h) => dnsDomainIs(h, ".corp.example");
function FindProxyForURL(url, host) {
if (isCorp(host)) {
return `DIRECT`;
}
return PROXY_A;
}
Open bad example in checkerGood
var PROXY_A = "PROXY proxy.corp.example:8080";
function isCorp(h) {
return dnsDomainIs(h, ".corp.example");
}
function FindProxyForURL(url, host) {
if (isCorp(host)) {
return "DIRECT";
}
return PROXY_A;
}
Open good example in checkerEngine behaviour
| Engine | Behaviour | Source |
|---|---|---|
| chromium | V8; current ECMAScript syntax parses. | code, verified 2026-10-04 · ref |
| firefox | SpiderMonkey; current ECMAScript syntax parses. | expert, unverified |
| pacparser | Depends on the bundled SpiderMonkey version; older builds reject ES2015 syntax. | expert, unverified |
| winhttp | Reported ES5-level engine; ES2015 syntax is a parse error for the whole file. | expert, unverified |