PAC-C016 · isinnet-parameter-order

isInNet arguments in the wrong order

high · Correctness

isInNet(host, network, mask) is the order. isInNet("10.0.0.0", host, "255.0.0.0") compares the network literal against a mask derived from the hostname and is false for every request.

Why it matters

With the network literal in the first position and host in the second, the function tries to resolve 10.0.0.0 (fine, it is already an address) and to interpret the hostname as a network address, which fails. The result is always false and the internal-network exception never applies. The call looks plausible enough that reviewers miss it.

How to fix

Write isInNet(host, "10.0.0.0", "255.0.0.0").

Examples

Bad

function FindProxyForURL(url, host) {
  if (isInNet("10.0.0.0", host, "255.0.0.0")) {
    return "DIRECT";
  }
  return "PROXY proxy.corp.example:8080";
}
Open bad example in checker

Good

function FindProxyForURL(url, host) {
  if (isInNet(host, "10.0.0.0", "255.0.0.0")) {
    return "DIRECT";
  }
  return "PROXY proxy.corp.example:8080";
}
Open good example in checker

Related rules

References