PAC-C008 · loopback-only-127-0-0-1

Only 127.0.0.1 excluded instead of 127.0.0.0/8

low · Correctness · Top 20 #18

The entire 127.0.0.0/8 block is loopback. A PAC that only exempts 127.0.0.1 sends 127.0.0.2 or 127.1.2.3 (used by local development tools and some agents) to the proxy, where the connection fails.

Why it matters

Local services bind to any address in 127.0.0.0/8, not only 127.0.0.1; developer tooling, local agents and container runtimes use other loopback addresses routinely. A request to such an address sent via the proxy ends on the proxy’s own loopback interface or fails. Also consider localhost as a name and ::1 for IPv6 (PAC-C012).

How to fix

Use host == "localhost" || (IP literal && isInNet(host, "127.0.0.0", "255.0.0.0")).

Examples

Bad

function FindProxyForURL(url, host) {
  if (host == "127.0.0.1" || host == "localhost") {
    return "DIRECT";
  }
  return "PROXY proxy.corp.example:8080";
}
Open bad example in checker

Good

function FindProxyForURL(url, host) {
  if (host == "localhost" || host == "::1" ||
      (/^\d+\.\d+\.\d+\.\d+$/.test(host) && isInNet(host, "127.0.0.0", "255.0.0.0"))) {
    return "DIRECT";
  }
  return "PROXY proxy.corp.example:8080";
}
Open good example in checker

Related rules

References