Introduction¶
The DeepSeek Harness (DSH) Web UI is the entry point for managing agents and configuring the system. For DSH instances directly exposed to the public network or a LAN, adding access control is necessary. The dsh-auth plugin provides a username/password-based authentication gateway for DSH Web, addressing security risks that may arise from direct port access.
Plugin Overview¶
This authentication plugin was published by the maintainer optttt and is licensed under the MIT License. It adds a login protection layer at the Web tier, ensuring that only authorized users can access the DSH management interface.
Installation and Enablement¶
Install the plugin via DSH’s package manager.
dsh plugin --profile web add @tyler9061/dsh-auth
After installation is complete, restart dsh web.
Core Features¶
The plugin provides the following key features:
- Login Authentication: Accessing the Web UI requires a username and password.
- Idle Logout: If a session remains inactive for a long time, the system logs out automatically.
- Session Expiration: Supports configuring the maximum lifetime of a session.
- Single Sign-On: When enabled, a new login forces logout of other existing sessions.
- UI Settings: Modify credentials and expiration time in the Web UI under Settings > Auth.
- Command-Line Operations: Provides CLI tools to reset passwords and change usernames.
- Login History: Records recent successful login information (IP, time, geographic location).
Typical Usage¶
After the initial installation and startup, the console prints the default username and password (the default username is admin). When accessing the Web UI, the browser is redirected to the /login page automatically.
Reset Password:
- Print a new random password:
dsh web p
- Set a specific password:
dsh web p mypass
Change Username:
Usernames are limited to 3-32 characters and may include letters, numbers, underscores, and hyphens.
dsh web u newname
In the Web UI, go to the Settings > Auth menu to manually modify the username, password, idle logout timeout, maximum session lifetime, and to manage single sign-on status and view login history.
Network Access and Reverse Proxy¶
The plugin runs in reverse proxy mode, with the following configuration details:
- Local Binding: The actual internal service binds only to
127.0.0.1. - Proxy Port: The plugin runs a reverse proxy on
0.0.0.0:<lanPort>, defaulting to port3080. This port can be overridden with theDSH_AUTH_PORTenvironment variable. - LAN Access: Because of the reverse proxy, all
/apiRPC endpoints (including settings, files, SCM, etc.) can be accessed by LAN clients. However, the authentication gateway still protects all content, and no operation is possible without logging in. - WebSocket Support: The proxy correctly handles WebSocket upgrades, ensuring connections are established normally.
Security Considerations¶
- Production Environments: Using HTTPS in production environments is strongly recommended.
- Lost Keys: The plugin’s encryption key is stored in
$DSH_HOME/auth.keywith permissions set to 0600. If this file is lost, the data cannot be decrypted, and the password must be reset using thedsh web pcommand. - Initial Password: After the first login, the default
adminpassword should be changed immediately.
Summary¶
dsh-auth provides DSH Web with standard login authentication, session management, and login auditing capabilities. Through both command-line and Web UI operations, it balances convenience and security. For users who want to harden exposure of DSH Web ports, this is a basic and necessary component.