Only 127.0.0.1 excluded instead of 127.0.0.0/8
low
The entire 127.0.0.0/8 block is loopback. A PAC that only exempts 127.0.0.1 sends 127.0.0.2 or 127.1.2.3 (used by local development tools and some agents) to the proxy, where the connection fails.
Why it matters
Local services bind to any address in 127.0.0.0/8, not only 127.0.0.1; developer
tooling, local agents and container runtimes use other loopback addresses routinely. A
request to such an address sent via the proxy ends on the proxy’s own loopback interface
or fails. Also consider localhost as a name and ::1 for IPv6 (PAC-C012).
How to fix
Use host == "localhost" || (IP literal && isInNet(host, "127.0.0.0", "255.0.0.0")).
Examples
Bad
function FindProxyForURL(url, host) {
if (host == "127.0.0.1" || host == "localhost") {
return "DIRECT";
}
return "PROXY proxy.corp.example:8080";
}
Open bad example in checkerGood
function FindProxyForURL(url, host) {
if (host == "localhost" || host == "::1" ||
(/^\d+\.\d+\.\d+\.\d+$/.test(host) && isInNet(host, "127.0.0.0", "255.0.0.0"))) {
return "DIRECT";
}
return "PROXY proxy.corp.example:8080";
}
Open good example in checkerRelated rules
- RFC 1918 range with the wrong mask PAC-C007
- IP range matched as a text prefix PAC-X006
- IPv4 loopback/private ranges handled, IPv6 equivalents not PAC-C012