PAC loaded from a file path or SMB share
medium
A PAC on a file share is executable policy stored where many people can write. Access control on the share, not on the proxy team, now decides who controls routing. Chromium also no longer accepts file-scheme PAC URLs.
Why it matters
The PAC body is code that every client runs. On an SMB share or a local path its integrity
depends on NTFS/share permissions that are rarely reviewed with that in mind. Chromium
stopped supporting file:// PAC URLs years ago, so the setting silently does nothing in
those browsers while Windows components may still use it. Serve the PAC from a web server
with a restricted document root, over https, with fetch logging (PAC-D001).
How to fix
Move the PAC to an https web server with write access restricted to the proxy team.
Examples
Engine behaviour
| Engine | Behaviour | Source |
|---|---|---|
| chromium | file: PAC URLs are not supported. | expert, unverified |
Related rules
- PAC served over plain HTTP PAC-D001