Introduction

DeepSeek Harness (DSH) is an agent development platform. When deploying the Web GUI, login protection is usually required to distinguish different users or control access permissions. This plugin provides the DSH Cordis plugin ecosystem with a zero-dependency, configuration-only authentication solution, supporting identity verification via username/password, OAuth 2.0, and multiple cryptocurrency wallets.

Plugin Overview

  • Name: dsh-auth-plugin
  • Maintainer: v1xingyue
  • Category: admin-security
  • License: MIT
  • Core value: zero-dependency core (pure Node.js implementation), supports password, generic OAuth 2.0 (built-in GitHub/Google/Discord templates), and Solana/EVM wallet login, configuration-only integration.

Core Features

The plugin provides the following capabilities:

  1. Username + password login: Supports storing user credentials using scrypt hashes.
  2. Generic OAuth 2.0 login: Supports any authorization code provider (such as GitHub, Google, Discord) via configuration.
  3. Solana wallet login: Based on ed25519 signature verification; supports wallets such as Phantom.
  4. EVM wallet login: Supports Ethereum-based wallets (such as MetaMask) using EIP-191 personal_sign.
  5. Unified session management: Uses HMAC-SHA256 tokens and HttpOnly cookies to manage sessions, with revocation on logout.
  6. Zero-dependency core: No third-party pnpm/npm packages are required; uses Node.js native modules directly.
  7. Bundled installation: Supports one-click installation via the dsh plugin command.

Installation and Configuration

The plugin can be installed directly into the specified Web profile using the dsh plugin command.

dsh plugin --profile web add dsh-auth-plugin

After installation, insert the configuration into ~/.dsh/profiles/web/cordis.patch.yml. A minimal configuration example is as follows:

- insert:
    - id: auth
      name: "./dsh-auth-plugin.js"
      config:
        users:
          admin: admin123

Restart the dsh web service to apply the configuration.

Usage Notes

  • EVM wallet dependencies: EVM wallet login requires the @noble/curves and @noble/hashes libraries (optional installation; if missing, the feature is automatically disabled).
  • Solana allowlist: When configuring Solana wallet login, the allowlist field is required to restrict the wallet public keys allowed to log in.
  • Core mechanism: The plugin operates as the sole fallback seat holder and intercepts unauthenticated requests. It supports ed25519 signature verification and the EIP-191 standard.

Summary

This plugin provides DSH with a unified login entry point that bridges traditional account systems and Web3 wallet systems, while keeping the core implementation lightweight. For scenarios that require quickly adding secure access control to the DeepSeek Harness Web interface, this is a direct solution. Refer to the SkillHub plugin directory or the GitHub repository for details.