PAC-K017 · zscaler-client-connector-legacy-pac-parser

ES2015+ syntax and the Zscaler Client Connector legacy PAC parser

medium · Compatibility across engines

Zscaler Client Connector evaluates the App Profile and Forwarding Profile PAC files itself. Older versions offered a legacy parser next to the V8-based one; whether the legacy parser accepts ES2015 syntax is undocumented, so a modern-syntax PAC may fail on an old client while browsers run it.

Why it matters

The app profile settings document a “V8 JavaScript based PAC Parser” option and state that Zscaler Client Connector 4.9 and later for Windows (4.3 and later for macOS) use the V8 parser regardless of the setting. Before that, the legacy parser could be in use. Zscaler does not document which JavaScript level the legacy parser supports. This rule is a draft until a lab run with an old client shows whether let, const, arrow functions or template literals load. Until then, treat the client like WinHTTP (PAC-K001): write ES5.

How to fix

Write ES5 syntax (var, function expressions, string concatenation) in PAC files that Zscaler Client Connector downloads, or make sure every client runs 4.9+ (Windows) / 4.3+ (macOS).

Examples

Bad

function FindProxyForURL(url, host) {
  const internal = [".corp.example", ".lab.example"];
  for (const suffix of internal) {
    if (dnsDomainIs(host, suffix)) {
      return "DIRECT";
    }
  }
  return "PROXY ${GATEWAY}:80; PROXY ${SECONDARY_GATEWAY}:80";
}
Open bad example in checker

Good

function FindProxyForURL(url, host) {
  if (dnsDomainIs(host, ".corp.example") || dnsDomainIs(host, ".lab.example")) {
    return "DIRECT";
  }
  return "PROXY ${GATEWAY}:80; PROXY ${SECONDARY_GATEWAY}:80";
}
Open good example in checker

Draft (awaiting a lab run). Zscaler pack only; PAC-K001 already covers the browser side.

Related rules

References