PAC-K009 · host-not-lowercased

Case-sensitive host comparisons without lower-casing host

low · Compatibility across engines

Chromium and Firefox lower-case the hostname before calling the PAC; WinHTTP is reported to pass it as typed. Lower-casing host once at the top of the function makes the file behave the same everywhere.

Why it matters

DNS names are case-insensitive, string comparisons in JavaScript are not. Where the engine normalises host to lower case the extra call is a no-op; where it does not, a user typing HTTPS://Intranet.Corp.Example misses every lower-case rule and takes the default route. One line, host = host.toLowerCase();, removes the dependency on engine behaviour. The literals must be lower case as well (PAC-C018).

How to fix

Add host = host.toLowerCase(); as the first statement of FindProxyForURL and keep all literals lower case.

Examples

Bad

function FindProxyForURL(url, host) {
  if (dnsDomainIs(host, ".corp.example")) {
    return "DIRECT";
  }
  return "PROXY proxy.corp.example:8080";
}
Open bad example in checker

Good

function FindProxyForURL(url, host) {
  host = host.toLowerCase();
  if (dnsDomainIs(host, ".corp.example")) {
    return "DIRECT";
  }
  return "PROXY proxy.corp.example:8080";
}
Open good example in checker

Engine behaviour

EngineBehaviourSource
chromiumhost is passed lower-cased (URL canonicalisation).doc, unverified
pacparserPasses host as given to pactester; case-sensitive comparison.lab, verified 2026-05-20
winhttpReported to pass the hostname as typed.expert, unverified

Source: code = read in the engine's source, doc = vendor documentation, lab = observed in a lab run, expert = practitioner knowledge, not yet verified.

Related rules

References