PAC-E015 · invisible-characters

Zero-width or bidirectional control characters

high · Errors and robustness

Zero-width spaces, joiners, bidi marks, no-break spaces or a mid-file BOM. They are invisible in editors but change what a string literal contains, so a pattern that looks right never matches.

Why it matters

dnsDomainIs(host, ".corp.example") with a U+200B inside the literal is a different string from the visible one and matches nothing. The branch becomes dead code and the request falls through to the default route. Bidi override characters (U+202E and friends) can also make code read differently from how it executes. These characters arrive through copy-paste from web pages, tickets and chat tools. In code position (outside strings and comments) some of them are syntax errors; a no-break space (U+00A0) is valid whitespace in JavaScript but still a sign of pasted text.

How to fix

Retype the affected literal; reject any byte outside 7-bit ASCII in CI (`LC_ALL=C grep -nP '[^\x00-\x7F]'`).

Examples

Bad

function FindProxyForURL(url, host) {
  if (dnsDomainIs(host, ".corp.​example")) {
    return "DIRECT";
  }
  return "PROXY proxy.corp.example:8080";
}
Open bad example in checker

Good

function FindProxyForURL(url, host) {
  if (dnsDomainIs(host, ".corp.example")) {
    return "DIRECT";
  }
  return "PROXY proxy.corp.example:8080";
}
Open good example in checker

The bad example contains a zero-width space (U+200B) after "corp." in the pattern.

Related rules

References