PAC-C018 · uppercase-pattern-literal

Upper-case letters in a hostname pattern

medium · Correctness · Top 20 #20

Browsers hand the PAC a lower-cased hostname. A pattern such as "Intranet.Corp.Example" never matches in Chromium or Firefox. Where engines do not lower-case (WinHTTP), the comparison is case-sensitive anyway, so patterns must be lower case and host should be lower-cased explicitly.

Why it matters

URL parsing in Chromium and Firefox follows the URL Standard, which lower-cases ASCII domain names, so host arrives lower-cased and the pattern must be lower-case to match. WinHTTP is reported to pass the hostname as typed, so there the same upper-case pattern matches only if the user typed it that way. The robust idiom is to lower-case both sides: host = host.toLowerCase(); at the top of the function and lower-case literals everywhere (PAC-K009). Mixed-case literals are therefore always wrong.

How to fix

Write all hostname literals in lower case and add host = host.toLowerCase(); at the start of the function.

Examples

Bad

function FindProxyForURL(url, host) {
  if (dnsDomainIs(host, ".Corp.Example")) {
    return "DIRECT";
  }
  return "PROXY proxy.corp.example:8080";
}
Open bad example in checker

Good

function FindProxyForURL(url, host) {
  host = host.toLowerCase();
  if (dnsDomainIs(host, ".corp.example")) {
    return "DIRECT";
  }
  return "PROXY proxy.corp.example:8080";
}
Open good example in checker

Engine behaviour

EngineBehaviourSource
chromiumhost is passed lower-cased (URL canonicalisation).doc, unverified
firefoxhost is passed lower-cased (URL canonicalisation).doc, unverified
pacparserPasses host as given; dnsDomainIs(host, ".example.com") does not match "Example.com".lab, verified 2026-05-20
winhttpReported not to lower-case host; pattern comparison is case-sensitive.expert, unverified

Source: code = read in the engine's source, doc = vendor documentation, lab = observed in a lab run, expert = practitioner knowledge, not yet verified.

Related rules

References