Introduction

DSH provides a local Web UI (usually listening on port 3080). To access this UI from a smartphone or tablet within a LAN, a reverse proxy or port forwarding is usually required. The dsh-lan-pass plugin provides a simple password gate solution, allowing devices on the same LAN to directly access the local DSH Web UI with a password.

Plugin Overview

This is a client plugin. It uses a password verification mechanism to allow smartphones or tablets to access the DSH Web UI on the local machine (localhost/127.0.0.1) within the same LAN. Because they share the same backend, sessions and input/output are synchronized in real time with the computer. The plugin includes a crypto.randomUUID polyfill to handle non-secure HTTP contexts.

Installation

dsh plugin --profile web add link:/path/to/lan-pass

Configuration and Startup

After installation, the default password is deepseekyyds. Since this password is public, there is a security risk; change it as soon as possible.

There are two ways to change it:
1. Set the environment variable DSH_LAN_PASSWORD.
2. Edit %USERPROFILE%\.dsh\.credentials.yaml and add:

DSH_LAN_PASSWORD: 你的新密钥

Restart dsh after making changes.

When starting the DSH Web service, you must specify the listening address:

dsh web --host 0.0.0.0

Also, allow TCP port 3080 in the firewall:

netsh advfirewall firewall add rule name="DSH Web 3080" dir=in action=allow protocol=TCP localport=3080

Then access http://<电脑局域网IP>:3080 in your phone’s browser and enter the password to enter the UI.

Security Boundaries

Password gate validation is completed on the server side. Cookies are HMAC tokens and marked as HttpOnly.

However, the plugin does not add global middleware to the webServer. In theory, devices that have not passed UI authentication can still make direct requests to /api/* endpoints.
Note:
1. Use only on trusted home LANs.
2. The password is transmitted over plain HTTP. Do not use important passwords; use a random string of at least 8 characters.
3. For untrusted networks, use a reverse proxy solution (such as dsh-mobile-gate + HTTPS).

License

MIT

References

See the plugin directory: dsh-lan-pass
Source code address: GitHub