Introduction¶
The design philosophy of DeepSeek Harness (DSH) is “everything is a plugin.” In scenarios where multiple users on a single machine share one DSH process, the default Web interface displays the full set of workspaces to all logged-in users, lacking isolation. The dsh-multi-user plugin addresses this need through a login wall and view partitioning mechanism.
Plugin Overview¶
Name: dsh-multi-user
One-liner: Single-process multi-user workspace view partitioning for DeepSeek Harness: JWT-in-cookie login wall, per-user workspace/session partitioning, and admin user management.
Maintainer: nabin-qq273274877
Category: admin-security
License: MIT
Core Features¶
- JWT login wall: After mounting, accessing the home page requires authentication first. If no main administrator has been set, an initialization page is shown; otherwise, the login page is shown. After successful login, the plugin self-signs a JWT and writes it into an HttpOnly Cookie.
- Per-user workspace/session filtering: Each user, including the main administrator, maintains a list of added workspace paths. Users can add arbitrary paths via the directory selector. Only added paths and the sessions under them are visible to that user; other users cannot see them.
- User management: After initialization, the main administrator can add, delete, reset passwords, and enable/disable sub-users in the “User Management” section of the settings page.
- Single-process non-intrusive architecture: No additional gateway process is required. It is integrated directly as a regular plugin, with low costs for installation and restoration.
Installation and Activation¶
Run the following command in your terminal to install the plugin:
npx @deepseek-ai/dsh plugin --profile web add dsh-multi-user
After installation, restart the dsh web process to activate the plugin.
Typical Usage¶
- Initialize the main administrator: Visit
http://127.0.0.1:3080/and set up the main administrator account as prompted by the page. - Add sub-users: Log in with the main administrator account, go to the “User Management” area of the settings page, and add sub-users.
- Add workspaces as a user: After a sub-user logs in, use the directory selector in the sidebar to select a local path and add it to the workspace. That path and the sessions under it are visible only to that user.
Applicable Scenarios and Cautions¶
- Security boundary: This is not a strong isolation solution. All users within the same process share the
workspaceRegistry, and Agent tools can still operate on arbitrary paths on the host machine. - Uninstallation impact: After uninstallation,
sidebar.workspacesreverts to the official full workspace view, but the plugin data directory$DSH_HOME/plugins-data/dsh-multi-user/is retained.
Summary¶
This plugin is suitable for scenarios that require multi-user view partitioning and lightweight login verification on the same machine. It implements identity isolation using JWT-in-cookie and reduces administrative complexity by combining it with view filtering.