DSH Web’s sidebar footer currently does not have an entry for archived conversations, which are hidden by the system. To view archived records, users must query logs through other means, which is cumbersome and can easily blur the current conversation. The dsh-archived-conversations plugin provides an archived conversation list and read-only preview functionality on the DSH Web settings page, solving the problem of being unable to directly view archived history.

Plugin Overview

This plugin is maintained by user AKS1st and aims to address the need of DSH users to view archived sessions in the Web interface. It adds an entry to the settings panel, allowing users to browse the archived list and click an item to view a preview of recent messages. Because DSH clients limit archived sessions so that they cannot remain open, the plugin is designed for read-only preview and does not attempt to restore or open archived sessions.

How It Works

The plugin consists of a client and a host side that work together.

The host side (src/index.ts) registers an exact route GET /__archived-conversations/preview?sessionId=<id>. When the client requests a preview, the host reads the session log through sessionQuery.readSession, extracts the six most recent user/assistant text messages (each truncated to 400 characters), and returns JSON data.

The client (src/client/index.js) loads a static bundle via window.__ModuleLoader__.load and registers a settings.section entry (id: archived-conversations). The list data is obtained through DSH’s standard props, and after clicking an item, a fetch call is made to the host’s preview route.

Installation and Enablement

Make sure the system has Node.js 22.19 or a later version installed. The installation commands are as follows:

dsh plugin --profile web add github:AKS1st/dsh-archived-conversations
dsh web   # 重启 web 服务使 profile 生效

If you encounter the ERR_PNPM_GIT_DEP_PREPARE_NOT_ALLOWED error, the package must be added to the allowBuilds list in the profile’s pnpm-workspace.yaml and the operation retried.

Uninstall the plugin:

dsh plugin --profile web remove archived-conversations

Usage

  1. Open the DSH Web interface and go to the Settings page.
  2. Find the Archived Conversations entry (id: archived-conversations) in the navigation bar.
  3. A notice is displayed at the top of the page: unarchiving is not currently supported.
  4. Click any item in the list to view a read-only preview of the six most recent messages in that archived session at the bottom of the sidebar.

Security Design

The plugin implements multiple layers of protection:

  • IDOR protection: The preview route only responds to requests whose sessionId belongs to workspaceRegistry.archivedSessionIds. Active sessions and subagent sessions are not readable and return 404.
  • Session ID validation: The sessionId in a request must conform to the DSH specification (session- prefix + UUID/counter); otherwise it is rejected.
  • Minimal data exposure: Only the six most recent messages are returned, with each text length limited to 400 characters. Reasoning content, tool calls, and full logs are not returned.
  • XSS protection: Message text is rendered in the browser as React text nodes, automatically escaped, without using innerHTML or dangerouslySetInnerHTML.
  • Request restrictions: Response headers set Cache-Control: no-store and X-Content-Type-Options: nosniff. Only loopback socket requests are accepted, and cross-site requests are rejected.
  • No credential leakage: The plugin does not read or send any files, credentials, or system information.

Limitations and Notes

  • Unarchiving is not supported: DSH Host currently does not expose an unarchiveSession API, and the plugin cannot implement it by calling private methods. Once an archived session is cleared back to the “New Conversation” state, it cannot be recovered.
  • Preview limitations: The preview is limited to the six most recent messages and is also subject to the per-message character limit.
  • Environment requirement: Node.js 22.19 or a later version is required.
  • Activation method: After installing the plugin, the dsh web service must be restarted for the configuration to take effect.

This plugin uses the standard Web Server registration and Fetch communication pattern to provide users with a secure, controlled way to view archived sessions without changing DSH’s existing state management logic.