PAC-K014 · isinnet-with-ipv6

isInNet called with an IPv6 address

medium · Compatibility across engines

isInNet is defined for dotted-quad IPv4 addresses and masks. An IPv6 network or mask makes the test false on every engine; the IPv6-capable isInNetEx exists only in some engines.

Why it matters

The v1 helper parses four decimal octets. isInNet(host, "fd00::", "ffff::") is never true. isInNetEx(host, "fd00::/8") would work in Chromium and WinHTTP but throws in Firefox (PAC-K003). For the few IPv6 ranges that matter in a PAC (loopback, link-local, unique-local) a string prefix test is portable and sufficient.

How to fix

Use string tests for well-known IPv6 ranges (host == "::1", shExpMatch(host, "fe80:*")) or a guarded isInNetEx with fallback.

Examples

Bad

function FindProxyForURL(url, host) {
  if (isInNet(host, "fd00::", "ff00::")) {
    return "DIRECT";
  }
  return "PROXY proxy.corp.example:8080";
}
Open bad example in checker

Good

function FindProxyForURL(url, host) {
  if (shExpMatch(host, "fd*:*") || shExpMatch(host, "fc*:*")) {
    return "DIRECT";
  }
  return "PROXY proxy.corp.example:8080";
}
Open good example in checker

Related rules

References