Introduction¶
The core design philosophy of DeepSeek Harness (DSH) is “everything is a plugin.” When using the default client connection handling, there is typically a lack of fine-grained authorization capabilities for external requests, making it impossible to enforce specific access control policies at remote entry points. The sperictao/dsh-client-connection-authz plugin aims to solve this problem. As a replacement for the official dsh-client-connection, it preserves the original behavior while adding a ConnectionRequestAuthorizer layer provided by an external authentication package, ensuring that only requests meeting specific conditions are allowed through.
Plugin Positioning¶
This is a replacement package that provides authentication capabilities for DeepSeek Harness client connections. It is maintained by sperictao and licensed under the MIT License. While preserving the original behavior of the official HTTP, shared/standalone RPC, WebSocket, and browser client, the plugin controls connection requests by injecting authorization logic.
Core Features¶
- Behavior preservation: Fully preserves the HTTP, RPC, WebSocket, and browser client behavior of the official built-in connection.
- Authorization interception: Adds a
ConnectionRequestAuthorizerbefore all remote entry points, with the specific authorization logic implemented by an external plugin. - Built-in disablement: Disables the built-in
@deepseek-ai/dsh-client-connectionthrough a dual-matching mechanism (id + name), preventing accidental disruption of other plugins that reuse the same id. - Mandatory injection: Forces injection of
connectionRequestAuthorizerand does not provide an anonymous-mode fallback. If the authentication plugin is missing or fails configuration, connection startup is refused. - Local bypass protection: A valid local bypass must satisfy both loopback Host and loopback TCP peer; merely spoofing
Host: 127.0.0.1still proceeds to the authorizer. - Browser security: On the browser side, it replaces the official bundle and verifies the unique id to prevent silent drift.
Installation and Enablement¶
This plugin is intentionally not meant to be enabled standalone; it must be installed together with an authentication package that provides ConnectionRequestAuthorizer.
Assuming we want to install it along with the dsh-auth-tailscale authentication package, the command is as follows:
# 使用 gh 登录凭据或已配置公钥的 SSH URL
dsh plugin --profile web add \
git+https://github.com/sperictao/dsh-client-connection-authz.git \
git+https://github.com/sperictao/dsh-auth-tailscale.git
Authorization Interface Description¶
The plugin relies on an external implementation of the ConnectionRequestAuthorizer interface, defined as follows:
interface ConnectionRequestAuthorizer {
authorize(facts: ConnectionRequestFacts):
| { allowed: true; principal: ConnectionPrincipal }
| { allowed: false; status: 401 | 403 }
}
The facts parameter includes the transport method, channel, endpoint, headers, TCP peer address, and the authority required by the target.
* trusted-host: ordinary API, ordinary RPC, and the two WebSocket downlinks.
* loopback: privileged APIs such as settings, credentials, and host file operations; the authentication plugin must explicitly grant higher privileges for remote calls to pass.
The execution order is fixed as: Host/Origin/DNS-rebinding fence → local loopback check → external authorizer → body reading/protocol upgrade/business handler.
Compatibility and Notes¶
- Dependency range: The compatibility of this package with DeepSeek Harness versions is determined solely by the dependency declaration (dependency range) in
package.json, such as^0.1.6-alpha.1. - Private repositories: The two repositories providing authentication functionality are currently private. Ensure that you are logged in to GitHub or have an SSH key configured when installing.
- Version compatibility: Compatible with DeepSeek Harness
0.1.0-rc.xand the dependency range^0.1.6-alpha.1.
Summary¶
This plugin provides a controllable authorization layer for DSH client connections, making it suitable for scenarios that require strict control over remote access permissions. Developers must implement the ConnectionRequestAuthorizer interface themselves and install the plugin together with the corresponding authentication package.