FindProxyForURLEx entry point
medium
FindProxyForURLEx is the PAC v2 entry point from Microsoft's IPv6 extensions. Chromium and Firefox ignore it and call FindProxyForURL. A file that relies on the Ex function alone has no effect in browsers.
Why it matters
WinHTTP prefers FindProxyForURLEx when the IPv6 extensions are enabled and falls back to
FindProxyForURL. Browsers do not know the Ex entry point. Defining both is legal but
doubles the logic that has to be kept in sync; defining only the Ex form leaves browsers
without a PAC (PAC-E002 reports the missing standard function). Unless the deployment is
WinHTTP-only, keep the standard function as the single source of truth.
How to fix
Keep FindProxyForURL as the entry point; if FindProxyForURLEx is required, make it delegate to FindProxyForURL.
Examples
Bad
function FindProxyForURLEx(url, host) {
if (isInNetEx(host, "fd00::/8")) {
return "DIRECT";
}
return "PROXY proxy.corp.example:8080";
}
Open bad example in checkerGood
function FindProxyForURL(url, host) {
if (shExpMatch(host, "fd*:*")) {
return "DIRECT";
}
return "PROXY proxy.corp.example:8080";
}
function FindProxyForURLEx(url, host) {
return FindProxyForURL(url, host);
}
Open good example in checkerEngine behaviour
| Engine | Behaviour | Source |
|---|---|---|
| chromium | Only FindProxyForURL is called. | code, verified 2026-10-04 · ref |
| winhttp | Calls FindProxyForURLEx when present and IPv6 extensions are enabled. | doc, unverified |
Related rules
- No FindProxyForURL function PAC-E002
- IPv6 extension functions (isInNetEx, dnsResolveEx, myIpAddressEx) PAC-K003