PAC-C023 · sse-proxy-for-non-http-schemes

Non-HTTP URLs reach a proxy that only accepts HTTP and HTTPS

low · Correctness

Cloud explicit proxies accept HTTP and HTTPS. Zscaler, Netskope and Palo Alto Networks all start their sample PAC files with a DIRECT for ftp: URLs; without such a guard, ftp: and other scheme requests from older clients are sent to a proxy that drops them.

Why it matters

Zscaler’s sample excludes FTP “since the service does not support native FTP”; Netskope states that “the only proxy settings currently supported are HTTP and HTTPS. Netskope drops all other traffic (e.g., FTP) sent to the proxy”; the Prisma Access sample has a “Bypass FTP” block and the guidelines say Explicit Proxy supports HTTP and HTTPS only. Modern browsers no longer speak FTP, which is why this is rated low, but PAC files are also consumed by system components and older clients, and the guard is a two-line convention in every vendor template. Netskope’s template does the inverse: it returns the proxy only when the URL starts with http: or https: and DIRECT otherwise.

How to fix

Add if (url.substring(0, 4) == "ftp:") return "DIRECT"; near the top, or return the proxy only for URLs that start with http or https.

Examples

Bad

function FindProxyForURL(url, host) {
  if (isPlainHostName(host)) {
    return "DIRECT";
  }
  return "PROXY ${GATEWAY}:80; PROXY ${SECONDARY_GATEWAY}:80";
}
Open bad example in checker

Good

function FindProxyForURL(url, host) {
  if (isPlainHostName(host)) {
    return "DIRECT";
  }
  if (url.substring(0, 4) == "ftp:") {
    return "DIRECT";
  }
  return "PROXY ${GATEWAY}:80; PROXY ${SECONDARY_GATEWAY}:80";
}
Open good example in checker

Zscaler, Netskope and Prisma Access packs.

Related rules

References