PAC-C001 · url-instead-of-host

Hostname pattern applied to url instead of host

high · Correctness · Top 20 #2

url is the complete request URL (scheme, host, port, path, query); host is the bare hostname. A hostname pattern tested against url either never matches or matches far too much. The most common PAC mistake.

Why it matters

The two arguments are different strings. shExpMatch(url, "www.example.com") is never true because url starts with http://. dnsDomainIs(url, ".example.com") is never true because url ends with a path. Authors then “fix” it with wildcards (*example.com*), which turns the test into a substring match over a string whose query part is controlled by whoever writes the link (PAC-X009).

There is a second trap: since Chrome 52, Chromium strips path, query and fragment from https:// URLs before calling the PAC, so any path-based decision only works for plain http. Hostname decisions belong on host; url is for scheme and, for http only, path.

How to fix

Use host for hostname checks (shExpMatch(host, "*.example.com"), dnsDomainIs(host, ".example.com")); use url only for scheme-based decisions.

Examples

Bad

function FindProxyForURL(url, host) {
  if (shExpMatch(url, "*.corp.example")) {
    return "DIRECT";
  }
  return "PROXY proxy.corp.example:8080";
}
Open bad example in checker

Good

function FindProxyForURL(url, host) {
  if (shExpMatch(host, "*.corp.example")) {
    return "DIRECT";
  }
  return "PROXY proxy.corp.example:8080";
}
Open good example in checker

Engine behaviour

EngineBehaviourSource
chromium >=52For https:// URLs the path, query, fragment and userinfo are stripped before FindProxyForURL is called (since Chrome 52; the opt-out was removed in Chrome 75); url is reduced to scheme://host:port/. http:// URLs are passed with path and query.doc, verified 2026-10-04 · ref
pacparsershExpMatch(url, "example.com") does not match http://example.com/x; the same pattern on host does.lab, verified 2026-05-20

Source: code = read in the engine's source, doc = vendor documentation, lab = observed in a lab run, expert = practitioner knowledge, not yet verified.

Related rules

References