PAC-C005 · isplainhostname-on-url

isPlainHostName called with url

medium · Correctness

isPlainHostName returns true for names without a dot. A URL always contains dots (and slashes), so isPlainHostName(url) is permanently false and the branch never fires.

Why it matters

The intent is almost always “single-label intranet names go direct”. Passing url defeats it: http://intranet/ contains a dot nowhere in the hostname but the string as a whole is not a plain hostname by the function’s definition, and real URLs contain dots in the host part anyway. The DIRECT branch for intranet names never applies and they go to the proxy, which may not be able to resolve them.

How to fix

Call isPlainHostName(host).

Examples

Bad

function FindProxyForURL(url, host) {
  if (isPlainHostName(url)) {
    return "DIRECT";
  }
  return "PROXY proxy.corp.example:8080";
}
Open bad example in checker

Good

function FindProxyForURL(url, host) {
  if (isPlainHostName(host)) {
    return "DIRECT";
  }
  return "PROXY proxy.corp.example:8080";
}
Open good example in checker

Related rules

References