Result assembled in a variable instead of returned per rule
low
var proxy = ...; if (a) proxy = ...; if (b) proxy = ...; return proxy; inverts the usual semantics (last match wins instead of first) and evaluates every condition, including DNS lookups, for every request.
Why it matters
PAC authors and reviewers expect first-match-wins, which a sequence of if (...) return
gives for free. The accumulator style evaluates all branches (so every expensive predicate
runs), lets a later broad rule override an earlier specific one, and spreads the decision
over the whole function. It is also where missing default assignments hide.
How to fix
Return directly from each branch and end with an unconditional default return.
Examples
Bad
function FindProxyForURL(url, host) {
var result = "PROXY proxy.corp.example:8080";
if (isPlainHostName(host)) { result = "DIRECT"; }
if (dnsDomainIs(host, ".corp.example")) { result = "DIRECT"; }
if (shExpMatch(host, "*.priority.example")) { result = "PROXY fast.corp.example:8080"; }
return result;
}
Open bad example in checkerGood
function FindProxyForURL(url, host) {
if (isPlainHostName(host)) { return "DIRECT"; }
if (dnsDomainIs(host, ".corp.example")) { return "DIRECT"; }
if (shExpMatch(host, "*.priority.example")) { return "PROXY fast.corp.example:8080"; }
return "PROXY proxy.corp.example:8080";
}
Open good example in checkerRelated rules
- Deeply nested conditions PAC-P008
- DNS-dependent rule placed before string rules PAC-P005