Introduction

DeepSeek Harness (DSH) supports plugin-based web deployment. By default, the web server entry point may lack host-side security policies. If the service is exposed to the public internet, unprotected API, SSE, and WebSocket endpoints may be directly accessible. Adding a unified authentication policy at the WebServer level is a basic step for improving web deployment security.

Plugin Overview

dsh-auth-lock is a DSH host-side plugin maintained by developer imchenmin. Its core function is to provide password authentication for DSH web deployments, covering all server routes registered for DSH API, SSE, WebSocket, and third-party plugins.

Core Features

The plugin mainly includes the following security and session management capabilities:

  1. Secure Storage and Validation
    Uses the Node.js scrypt algorithm for password derivation, with parameters N=32768, r=8, p=1, combined with a 128-bit random salt. Password verification uses constant-time comparison to ensure resistance against timing attacks. Plaintext passwords are never stored.

  2. Session Management
    Generates 256-bit random session tokens, retaining only the corresponding SHA-256 key in host memory. Uses HttpOnly, SameSite=Strict cookies, and automatically enables the Secure flag over TLS connections. Sessions have a default idle timeout of 10 minutes (configurable from 1 to 1440 minutes) and an absolute lifetime of 24 hours.

  3. Access Control
    By default, only local loopback addresses are allowed for initial setup, preventing remote takeover of new instances. Remote addresses are limited to 8 failed password attempts within a 15-minute window. Same-origin Origin checks are performed, and request body size is limited to 16 KiB.

  4. Generality
    Does not depend on other business plugins such as mobile, remote control, or pairing; it only depends on the DSH WebServer webserver/request and webserver/upgrade flows. The authentication policy is applied at the WebServer layer and automatically applies to all registered routes.

Installation and Activation

The plugin requires a Node.js version of: ^22.19.0 || >=24.0.0.

The installation command is as follows:

dsh plugin --profile web add github:imchenmin/dsh-auth-lock

After installation, check the DSH configuration (--dump-config) and confirm that cordis.patch.yml contains id: auth-lock. If the page reports a DSH version incompatibility, the plugin remains inactive, and uninstallation is recommended.

Typical Usage

  1. Initial Setup
    In the local browser on the host running DSH, visit http://127.0.0.1:<port>. The system will guide you to create a 4-16 character password or numeric PIN.

  2. Login and Access
    On subsequent visits, enter your password to pass authentication. After successful login, the page automatically refreshes or returns to the original page so that API, SSE, and WebSocket clients can re-establish connections.

  3. Change Password
    Go to the DSH settings panel and locate the “Access Lock” section. Enter the current password, new password, and confirmation of the new password in order. After saving, the system revokes old sessions and generates a new authentication key.

  4. Reset Password
    If you forget the password, you must reset it on the host running DSH. Stop dsh web and run:

    dsh plugin --profile web exec dsh-auth-lock-reset -- --yes
After restarting DSH, the system returns to the initial setup state.

Notes

  1. DSH Version Compatibility
    The plugin depends on specific DSH WebServer flows. On older DSH builds, the plugin remains inactive, and page logs explicitly indicate the issue and recommend uninstallation.

  2. Irreversibility
    The password verifier is irreversible, so the original password cannot be recovered. If forgotten, it must be reset using the command above.

  3. Environment Dependencies
    The plugin runs under host privileges of the DSH process. It is recommended to review the source code and license before installation.

  4. Ecosystem Changes
    DeepSeek Harness is evolving rapidly and may introduce changes that break extension-point compatibility. For long-term deployments, pin a Git commit or use a specifically released version.

Summary

dsh-auth-lock provides a lightweight but standardized authentication layer for DSH web deployments. Through password authentication, session management, and strict access control, it fills security gaps on the host side and is suitable for scenarios that require improved web service security.

  • Plugin catalog: https://www.skillhub.cn/plugins/imchenmin/dsh-auth-lock
  • Source code: https://github.com/imchenmin/dsh-auth-lock