Pattern matches an entire top-level domain
high
shExpMatch(host, "*.de") or dnsDomainIs(host, ".com") routes a whole country or generic TLD. In the usual "proxy everything, except..." PAC this bypasses inspection for millions of unrelated sites.
Why it matters
Enterprise PACs mostly send everything to the proxy and list exceptions that go DIRECT. A
TLD-only exception does not scope a policy to “our German sites”; it exempts every .de
site on the internet from the proxy. The usual cause is a typo: .example.de (the
subsidiary’s domain) was intended and .de was written.
Legitimate uses exist in multi-country deployments, e.g. routing *.il to an in-country
proxy. Those should be rare, deliberate and commented. Two-label public suffixes
(*.co. followed by a country code) have the same effect and are flagged when they are
in the sample list.
How to fix
Replace the TLD with the actual second-level domain, e.g. "*.example.de"; if the TLD routing is intended, add a comment saying so.
Examples
Bad
function FindProxyForURL(url, host) {
if (shExpMatch(host, "*.de")) {
return "DIRECT";
}
return "PROXY proxy.corp.example:8080";
}
Open bad example in checkerGood
function FindProxyForURL(url, host) {
if (host == "example.de" || shExpMatch(host, "*.example.de")) {
return "DIRECT";
}
return "PROXY proxy.corp.example:8080";
}
Open good example in checkerRelated rules
- dnsDomainIs pattern without a leading dot matches look-alike domains PAC-X003
- Very short or trailing-dot dnsDomainIs pattern PAC-C011