Preface¶
DeepSeek Harness (DSH) browser plugin channel packs each plugin into a single file (/plugins/<id>/client.js), and the dynamic bundler does not generate additional chunks or assets. The Monaco Editor is a multi-file distribution—including the loader, language-grouped modules, and stylesheets—so it cannot be delivered through the plugin channel.
The dsh-monaco plugin mounts its own routes to serve these files. The editor remains local: no CDN is required at runtime, and no third-party domains appear when tools read the operator source tree.
Installation and Activation¶
Install the plugin with the official command, then restart dsh after installation to activate the distribution.
dsh plugin --profile web add github:DevViking-Persike/dsh-monaco
After installation is complete, the Monaco Editor distribution will be mounted under the /monaco path.
Typical Usage¶
Monaco is served through its own AMD loader. In client plugins, load and configure it in the following order:
// 1. 加载 loader 脚本
await loadScript('/monaco/loader.js')
// 2. 配置路径,指向挂载点
window.require.config({ paths: { vs: '/monaco' } })
// 3. 加载编辑器主模块并创建实例
window.require(['vs/editor/editor.main'], () => {
window.monaco.editor.create(host, { value: '', language: 'typescript' })
})
Configuration¶
Customize the mount path with the route field. The default is /monaco.
- id: dsh-monaco
name: 'dsh-monaco'
config:
route: /vendor/monaco
Security and Limitations¶
The plugin does not register tools, prompt sections, or session events while serving static bytes, so it does not consume model context.
Security mechanisms include:
* Path traversal protection: Each request path is resolved to the distribution root and checked. resolve collapses .. first, so escape attempts—including percent-encoding—are caught by containment tests.
* Error handling: Failed reads under the root return 404, the same as unknown paths, so browsers cannot distinguish whether a file exists from the error.
* Method restrictions: Only GET and HEAD are supported; other methods return 405.
* Content types: Extensions not matched in the content-type table default to application/octet-stream, preventing browsers from misinterpreting files as scripts.
Known limitations:
* Web Workers: The plugin does not configure Monaco web workers. Consumers that want to use them must provide their own worker entry points and set MonacoEnvironment.
* Caching: Responses include an immutable one-week cache-control header. The distribution is pinned by the installed package version, but upgrading Monaco requires cache busting (changing the route) or a hard refresh.
* Distribution: The route serves the full distribution, including language modules that the page may never load.
Summary¶
This plugin addresses the pain point that DSH plugins requiring a real code editor inside the page normally need a CDN. By serving the Monaco Editor distribution over host HTTP routes, it keeps the editor local.
- Catalog page: https://www.skillhub.cn/plugins/DevViking-Persike/dsh-monaco
- GitHub: https://github.com/DevViking-Persike/dsh-monaco