Exceptions are caught and turned into DIRECT
high
A try/catch whose catch returns "DIRECT" converts every runtime problem (DNS failure, typo, engine quirk) into a proxy bypass. Errors should fail closed, towards the proxy.
Why it matters
Catching exceptions in a PAC is rarely useful; the engines already treat an uncaught exception as a script failure (which itself ends in DIRECT, PAC-E006). Catching and then returning DIRECT makes the fail-open explicit and permanent: a resolver outage, a renamed helper or any other bug now routes all affected traffic around the proxy without a trace in the engine’s error log. If a catch block exists, it should return the proxy, so that an error produces blocked or logged traffic instead of uninspected traffic.
How to fix
Remove the try/catch, or return the default proxy in the catch block.
Examples
Bad
function FindProxyForURL(url, host) {
try {
if (isInNet(dnsResolve(host), "10.0.0.0", "255.0.0.0")) {
return "DIRECT";
}
} catch (e) {
return "DIRECT";
}
return "PROXY proxy.corp.example:8080";
}
Open bad example in checkerGood
function FindProxyForURL(url, host) {
if (dnsDomainIs(host, ".corp.example")) {
return "DIRECT";
}
return "PROXY proxy.corp.example:8080";
}
Open good example in checker