PAC-K004 · findproxyforurlex-only

FindProxyForURLEx entry point

medium · Compatibility across engines

FindProxyForURLEx is the PAC v2 entry point from Microsoft's IPv6 extensions. Chromium and Firefox ignore it and call FindProxyForURL. A file that relies on the Ex function alone has no effect in browsers.

Why it matters

WinHTTP prefers FindProxyForURLEx when the IPv6 extensions are enabled and falls back to FindProxyForURL. Browsers do not know the Ex entry point. Defining both is legal but doubles the logic that has to be kept in sync; defining only the Ex form leaves browsers without a PAC (PAC-E002 reports the missing standard function). Unless the deployment is WinHTTP-only, keep the standard function as the single source of truth.

How to fix

Keep FindProxyForURL as the entry point; if FindProxyForURLEx is required, make it delegate to FindProxyForURL.

Examples

Bad

function FindProxyForURLEx(url, host) {
  if (isInNetEx(host, "fd00::/8")) {
    return "DIRECT";
  }
  return "PROXY proxy.corp.example:8080";
}
Open bad example in checker

Good

function FindProxyForURL(url, host) {
  if (shExpMatch(host, "fd*:*")) {
    return "DIRECT";
  }
  return "PROXY proxy.corp.example:8080";
}
function FindProxyForURLEx(url, host) {
  return FindProxyForURL(url, host);
}
Open good example in checker

Engine behaviour

EngineBehaviourSource
chromiumOnly FindProxyForURL is called.code, verified 2026-10-04 · ref
winhttpCalls FindProxyForURLEx when present and IPv6 extensions are enabled.doc, unverified

Source: code = read in the engine's source, doc = vendor documentation, lab = observed in a lab run, expert = practitioner knowledge, not yet verified.

Related rules

References