PAC-C002 · scheme-in-host-pattern

URL scheme in a host pattern

medium · Correctness

host never contains "://". A pattern such as "http://intranet.corp.example" can never match it; the branch is dead code and the request takes the default route.

Why it matters

host is just the hostname. A scheme prefix in the pattern makes the comparison permanently false. This usually happens when a URL was copied from a browser address bar into a host rule. The failure is silent: the intended exception never applies.

How to fix

Remove the scheme (shExpMatch(host, "intranet.corp.example")) or match the URL explicitly (shExpMatch(url, "http://intranet.corp.example/*")).

Examples

Bad

function FindProxyForURL(url, host) {
  if (shExpMatch(host, "http://intranet.corp.example")) {
    return "DIRECT";
  }
  return "PROXY proxy.corp.example:8080";
}
Open bad example in checker

Good

function FindProxyForURL(url, host) {
  if (host == "intranet.corp.example") {
    return "DIRECT";
  }
  return "PROXY proxy.corp.example:8080";
}
Open good example in checker

Related rules

References