PAC-B006 · plain-hostname-blanket-direct

isPlainHostName alone sends every single-label name direct

info · Best practice and maintainability

isPlainHostName(host) is true for any name without a dot, including a mistyped public name. The user then gets a local resolver error instead of the proxy's block page. Fine as a performance short-cut, weak as the only definition of "internal".

Why it matters

Single-label names are resolved through the client’s search list, so intranet becomes intranet.corp.example; that is why the DIRECT short-cut works. But googl or wiki typed without a suffix are also plain names and go DIRECT, where they fail at the resolver instead of reaching the proxy’s error page and logs. In environments that want all failures visible on the proxy, pair isPlainHostName with an explicit list of known short names or rely on dnsDomainIs(host, ".corp.example") for the internal definition.

How to fix

Keep isPlainHostName as a fast path only if a resolver-side failure for typos is acceptable; otherwise list the known short names explicitly.

Examples

Bad

function FindProxyForURL(url, host) {
  if (isPlainHostName(host)) {
    return "DIRECT";
  }
  return "PROXY proxy.corp.example:8080";
}
Open bad example in checker

Good

var shortNames = ["intranet", "wiki", "print"];
function FindProxyForURL(url, host) {
  if (shortNames.indexOf(host) >= 0 || dnsDomainIs(host, ".corp.example")) {
    return "DIRECT";
  }
  return "PROXY proxy.corp.example:8080";
}
Open good example in checker

Related rules

References