DeepSeek Harness (DSH)’s built-in browser trust boundary (trustedHosts) is intended to defend against DNS rebinding, not to perform identity authentication. As long as the Host header passes validation, anyone can use the Web UI. If you expose Harness on a non-loopback address (such as a public IP or LAN), visitors can use the interface without any credentials. The dsh-rgate plugin adds the missing authentication layer for self-hosted deployments.
Plugin Positioning¶
This is a remote access login gate that provides a full-page password wall, API restrictions, and session cookies. It is maintained by raomaiping-hash and addresses the lack of an authentication mechanism in the Web UI. This means IP scanners that encounter a public address see only a login page and cannot directly access Harness’s APIs.
Core Features¶
-
Full-Page Password Wall
By injecting a gate script intoindex.html, visitors from non-loopback sources (such as any source other than127.0.0.1,localhost, and::1) are redirected to the/rgate-loginlogin page. -
Complete API Restrictions
All/apiRPC requests return401when unauthenticated. The plugin registers its own/api/remote-auth.*endpoints and no longer proxies or masks Harness’s native API routes. -
Session Management
It uses thergate_sessioncookie, setsHttpOnlyandSameSite=Strict, and has a validity period of 7 days. Sessions are stored in memory, and logging out or changing the password clears all sessions. -
No
?token=URL
The plugin generates an HMAC-signedrgate_authcookie, completing the cookie validation in Harness’s nativedsh-client-connection, so visitors do not need to include a?token=parameter in the URL. -
Login Rate Limiting
Each client is limited to 5 failed attempts, after which exponential backoff is triggered (up to 16 minutes). It usesCf-Connecting-Ip(with Cloudflare Tunnel) as the client identifier to prevent a single attacker from locking out all users. -
Audit Logs
Successful/failed logins, lockouts, and password changes are logged to Harness logs (journald), and plaintext passwords are not recorded. -
Password Storage
Passwords are stored with salt using scrypt (N=16384, r=8, p=1) in~/.dsh/remote-auth.json(permissions 0600). -
Remote Access Settings
DSH’s settings plane provides entry points for remote access status, login/logout, and password changes. -
Origin Verification
Login and logout endpoints check the HTTP origin and reject cross-site form submissions.
Installation and Enablement¶
Install the plugin from GitHub (no build step):
dsh plugin --profile web add github:raomaiping-hash/dsh-rgate
After installation, restart the web profile. When the plugin is activated, it will output [rgate] Gate enabled … and generate a random password in ~/.dsh/remote-auth.json on first startup.
Typical Usage¶
- View Activation Logs
Confirm the plugin is active using the following command:
journalctl -u deepseek-harness | grep rgate
-
Recover a Forgotten Password
If you forgot the password, delete the~/.dsh/remote-auth.jsonfile directly and restart the Harness service. A new random password is printed in the service logs. -
Change Password
Use an authenticated session to send a POST request to/api/remote-auth.password. -
View Gate Status
Use/api/remote-auth.statusto check the current configuration, authentication status, and whether the access is loopback.
Applicable Scenarios and Notes¶
Applicable scenarios: Suitable for self-hosted deployments using a single password, for personal or small-team use.
Notes:
* Threat model: This plugin assumes the Harness process and host filesystem are trusted. If an attacker can read remote-auth.json or process memory, they already have host-level access. It is not a substitute for operating-system network hygiene, HTTPS termination, or upstream access control.
* WebSocket Not Protected: The WebSocket upgrades for /api/events.mux and /api/events.host are not restricted by the gate. Authenticated clients can still establish connections.
* In-Memory Sessions: Sessions are stored in memory, and restarting Harness forces all users to log out.
* Static Resources Public: Unauthenticated visitors can still access static resources (JS/CSS), but all data interactions still require passing through the API gate.
Summary¶
dsh-rgate provides a basic authentication layer for the DeepSeek Harness Web UI. Through its password wall and cookie-based session management, it effectively prevents direct scanning and unauthorized access to the Web interface. Combined with its audit logging and rate limiting mechanisms, it improves the security of self-hosted deployments.