Introduction

The design philosophy of DeepSeek Harness (DSH) is “everything is a plugin.” In scenarios where multiple users on a single machine share one DSH process, the default Web interface displays the full set of workspaces to all logged-in users, lacking isolation. The dsh-multi-user plugin addresses this need through a login wall and view partitioning mechanism.

Plugin Overview

Name: dsh-multi-user
One-liner: Single-process multi-user workspace view partitioning for DeepSeek Harness: JWT-in-cookie login wall, per-user workspace/session partitioning, and admin user management.
Maintainer: nabin-qq273274877
Category: admin-security
License: MIT

Core Features

  1. JWT login wall: After mounting, accessing the home page requires authentication first. If no main administrator has been set, an initialization page is shown; otherwise, the login page is shown. After successful login, the plugin self-signs a JWT and writes it into an HttpOnly Cookie.
  2. Per-user workspace/session filtering: Each user, including the main administrator, maintains a list of added workspace paths. Users can add arbitrary paths via the directory selector. Only added paths and the sessions under them are visible to that user; other users cannot see them.
  3. User management: After initialization, the main administrator can add, delete, reset passwords, and enable/disable sub-users in the “User Management” section of the settings page.
  4. Single-process non-intrusive architecture: No additional gateway process is required. It is integrated directly as a regular plugin, with low costs for installation and restoration.

Installation and Activation

Run the following command in your terminal to install the plugin:

npx @deepseek-ai/dsh plugin --profile web add dsh-multi-user

After installation, restart the dsh web process to activate the plugin.

Typical Usage

  1. Initialize the main administrator: Visit http://127.0.0.1:3080/ and set up the main administrator account as prompted by the page.
  2. Add sub-users: Log in with the main administrator account, go to the “User Management” area of the settings page, and add sub-users.
  3. Add workspaces as a user: After a sub-user logs in, use the directory selector in the sidebar to select a local path and add it to the workspace. That path and the sessions under it are visible only to that user.

Applicable Scenarios and Cautions

  • Security boundary: This is not a strong isolation solution. All users within the same process share the workspaceRegistry, and Agent tools can still operate on arbitrary paths on the host machine.
  • Uninstallation impact: After uninstallation, sidebar.workspaces reverts to the official full workspace view, but the plugin data directory $DSH_HOME/plugins-data/dsh-multi-user/ is retained.

Summary

This plugin is suitable for scenarios that require multi-user view partitioning and lightweight login verification on the same machine. It implements identity isolation using JWT-in-cookie and reduces administrative complexity by combining it with view filtering.

GitHub Repository
Plugin Catalog Page