PAC-B011 · no-proxy-failover

Single proxy without a fallback entry

info · Best practice and maintainability

A return with a single PROXY entry gives the browser no alternative when that proxy is down. A second proxy in the list keeps inspection in place during an outage; what should happen when all proxies are down is a design decision (see PAC-X014).

Why it matters

Browsers fail over along the list and remember a failed proxy for a while. With one entry there is no failover: users get connection errors until the proxy is back. A second proxy (or a load-balanced VIP that already hides the failover) is the normal answer. The finding is informational because single-proxy returns are legitimate behind a highly available VIP; the author should confirm which case applies.

How to fix

List a second proxy ("PROXY p1:8080; PROXY p2:8080") or point at a highly available address.

Examples

Bad

function FindProxyForURL(url, host) {
  return "PROXY proxy1.corp.example:8080";
}
Open bad example in checker

Good

function FindProxyForURL(url, host) {
  return "PROXY proxy1.corp.example:8080; PROXY proxy2.corp.example:8080";
}
Open good example in checker

Related rules

References