Case-sensitive host comparisons without lower-casing host
low
Chromium and Firefox lower-case the hostname before calling the PAC; WinHTTP is reported to pass it as typed. Lower-casing host once at the top of the function makes the file behave the same everywhere.
Why it matters
DNS names are case-insensitive, string comparisons in JavaScript are not. Where the engine
normalises host to lower case the extra call is a no-op; where it does not, a user typing
HTTPS://Intranet.Corp.Example misses every lower-case rule and takes the default route.
One line, host = host.toLowerCase();, removes the dependency on engine behaviour. The
literals must be lower case as well (PAC-C018).
How to fix
Add host = host.toLowerCase(); as the first statement of FindProxyForURL and keep all literals lower case.
Examples
Bad
function FindProxyForURL(url, host) {
if (dnsDomainIs(host, ".corp.example")) {
return "DIRECT";
}
return "PROXY proxy.corp.example:8080";
}
Open bad example in checkerGood
function FindProxyForURL(url, host) {
host = host.toLowerCase();
if (dnsDomainIs(host, ".corp.example")) {
return "DIRECT";
}
return "PROXY proxy.corp.example:8080";
}
Open good example in checkerEngine behaviour
| Engine | Behaviour | Source |
|---|---|---|
| chromium | host is passed lower-cased (URL canonicalisation). | doc, unverified |
| pacparser | Passes host as given to pactester; case-sensitive comparison. | lab, verified 2026-05-20 |
| winhttp | Reported to pass the hostname as typed. | expert, unverified |