PAC-C015 · scheme-pinned-url-pattern

URL pattern pinned to http:// only

info · Correctness

A url pattern starting with "http://" does not match "https://". Most sites are https today; unless different routing for plain http is intended, the rule is probably outdated.

Why it matters

Scheme-specific routing is legitimate (e.g. legacy intranet applications on plain http). But many http:// patterns were written when the site was http and silently stopped matching when it moved to https. The check only asks the author to confirm the intent; hostname decisions should be on host, which is scheme-independent (PAC-C001).

How to fix

Match on host if the scheme does not matter; otherwise cover both schemes ("*://www.corp.example/*") and comment why.

Examples

Bad

function FindProxyForURL(url, host) {
  if (shExpMatch(url, "http://www.corp.example/*")) {
    return "DIRECT";
  }
  return "PROXY proxy.corp.example:8080";
}
Open bad example in checker

Good

function FindProxyForURL(url, host) {
  if (host == "www.corp.example") {
    return "DIRECT";
  }
  return "PROXY proxy.corp.example:8080";
}
Open good example in checker

Related rules