DeepSeek Harness (DSH)’s built-in browser trust boundary (trustedHosts) is intended to defend against DNS rebinding, not to perform identity authentication. As long as the Host header passes validation, anyone can use the Web UI. If you expose Harness on a non-loopback address (such as a public IP or LAN), visitors can use the interface without any credentials. The dsh-rgate plugin adds the missing authentication layer for self-hosted deployments.

Plugin Positioning

This is a remote access login gate that provides a full-page password wall, API restrictions, and session cookies. It is maintained by raomaiping-hash and addresses the lack of an authentication mechanism in the Web UI. This means IP scanners that encounter a public address see only a login page and cannot directly access Harness’s APIs.

Core Features

  1. Full-Page Password Wall
    By injecting a gate script into index.html, visitors from non-loopback sources (such as any source other than 127.0.0.1, localhost, and ::1) are redirected to the /rgate-login login page.

  2. Complete API Restrictions
    All /api RPC requests return 401 when unauthenticated. The plugin registers its own /api/remote-auth.* endpoints and no longer proxies or masks Harness’s native API routes.

  3. Session Management
    It uses the rgate_session cookie, sets HttpOnly and SameSite=Strict, and has a validity period of 7 days. Sessions are stored in memory, and logging out or changing the password clears all sessions.

  4. No ?token= URL
    The plugin generates an HMAC-signed rgate_auth cookie, completing the cookie validation in Harness’s native dsh-client-connection, so visitors do not need to include a ?token= parameter in the URL.

  5. Login Rate Limiting
    Each client is limited to 5 failed attempts, after which exponential backoff is triggered (up to 16 minutes). It uses Cf-Connecting-Ip (with Cloudflare Tunnel) as the client identifier to prevent a single attacker from locking out all users.

  6. Audit Logs
    Successful/failed logins, lockouts, and password changes are logged to Harness logs (journald), and plaintext passwords are not recorded.

  7. Password Storage
    Passwords are stored with salt using scrypt (N=16384, r=8, p=1) in ~/.dsh/remote-auth.json (permissions 0600).

  8. Remote Access Settings
    DSH’s settings plane provides entry points for remote access status, login/logout, and password changes.

  9. Origin Verification
    Login and logout endpoints check the HTTP origin and reject cross-site form submissions.

Installation and Enablement

Install the plugin from GitHub (no build step):

dsh plugin --profile web add github:raomaiping-hash/dsh-rgate

After installation, restart the web profile. When the plugin is activated, it will output [rgate] Gate enabled … and generate a random password in ~/.dsh/remote-auth.json on first startup.

Typical Usage

  1. View Activation Logs
    Confirm the plugin is active using the following command:
   journalctl -u deepseek-harness | grep rgate
  1. Recover a Forgotten Password
    If you forgot the password, delete the ~/.dsh/remote-auth.json file directly and restart the Harness service. A new random password is printed in the service logs.

  2. Change Password
    Use an authenticated session to send a POST request to /api/remote-auth.password.

  3. View Gate Status
    Use /api/remote-auth.status to check the current configuration, authentication status, and whether the access is loopback.

Applicable Scenarios and Notes

Applicable scenarios: Suitable for self-hosted deployments using a single password, for personal or small-team use.

Notes:
* Threat model: This plugin assumes the Harness process and host filesystem are trusted. If an attacker can read remote-auth.json or process memory, they already have host-level access. It is not a substitute for operating-system network hygiene, HTTPS termination, or upstream access control.
* WebSocket Not Protected: The WebSocket upgrades for /api/events.mux and /api/events.host are not restricted by the gate. Authenticated clients can still establish connections.
* In-Memory Sessions: Sessions are stored in memory, and restarting Harness forces all users to log out.
* Static Resources Public: Unauthenticated visitors can still access static resources (JS/CSS), but all data interactions still require passing through the API gate.

Summary

dsh-rgate provides a basic authentication layer for the DeepSeek Harness Web UI. Through its password wall and cookie-based session management, it effectively prevents direct scanning and unauthorized access to the Web interface. Combined with its audit logging and rate limiting mechanisms, it improves the security of self-hosted deployments.

Plugin Catalog
GitHub Repository