DeepSeek Harness (DSH) uses a plugin-based architecture. Binding the official Web UI to 0.0.0.0 creates a remote code execution risk, while binding it to 127.0.0.1 prevents phone access. The dsh-ios-control plugin securely exposes the official UI to the LAN by running an authenticated reverse-proxy gateway on a separate port, enabling phone QR-code remote control of the agent on the PC.
Plugin Positioning¶
This is a personally customized plugin based on dsh-remote-link (MIT License), maintained by developer Hjay1101. It mainly addresses the question of “how to control a DSH agent from a mobile device without sacrificing security.”
Core Features¶
- Phone QR-code control: One-time pairing via QR code or short code; phone browsers can directly open the official UI for control.
- Session persistence: With
pairing.persistSessionsenabled, paired devices remain logged in after a DSH process restart. - Session fork tool (
fork_session): The model can call this tool to create a child session using the most recent turn as the boundary, inheriting context without affecting the current session. - Link keep-alive: To address the lack of heartbeat in DSH downstream event streams, the gateway injects WS ping messages when idle, preventing connections from being silently dropped by carrier NAT.
- Status monitoring: Provides a
/statuspage that displays real-time connection RTT, device identity, upstream health, and keep-alive counts. - Device management: Supports viewing the list of connected devices, kicking old devices, or generating new pairing codes.
- MiMo Code support: Can act as an authentication gateway, converting the mobile UI of the MiMo Code service into a form controllable from a phone.
- Authentication gateway: Based on a loopback reverse proxy, provides HMAC challenge-response authentication and HttpOnly cookie session management.
Installation and Activation¶
Install the plugin via the official CLI:
dsh plugin --profile web add ./dsh-ios-control
After installation, the plugin takes over the DSH Web profile and adds a remote-link configuration item to the configuration file. The default binding address is 0.0.0.0, and the port is 3081.
Typical Usage¶
Pair a device: Enter a command in the chat box to obtain one-time pairing information.
Input:
give me a pairing code
Output: Includes the QR code URL, an ASCII QR code image, and a 6-digit short code.
Manage devices: Query or clean up paired devices.
Input:
show who has connected to me / kick my old iPad
Tool:remote_devices
Create a child session: Try a different conversation branch.
Input:
fork it and try another direction
Tool:fork_session
Manual pairing: If the phone cannot scan the QR code, open the pairing address on any device.
Access:
http://<IP>:3081/pairand enter the short code.
View status: View link health in a desktop browser.
Access:
http://127.0.0.1:<port>/status
Use Cases and Notes¶
This plugin suits developers who need to debug or interact with a locally running DSH agent anytime and anywhere.
Security limitations:
* Based on HTTP transport, LAN sniffers can copy the cookie to hijack the session (HTTP ceiling).
* If the gateway is bound to a non-loopback address, has no password, and pairing is disabled, it refuses to load.
* The pairing secret exists only in the URL fragment; the server stores only the SHA-256 digest, which expires after 5 minutes.
MiMo mode:
* In MiMo Code mode, management tools in the chat box (such as remote_qr, fork_session) are unavailable; pairing is handled by the /qr page.
Dependencies and runtime:
* Zero runtime dependencies and a pure Node.js implementation.
* When persistSessions is set to true in the configuration file, session summaries are written with 0600 permissions to the $DSH_HOME/remote-link/ directory.