Preface

By default, the Web service of DeepSeek Harness (DSH) usually listens only to the local address. To access or debug it directly from other devices on a local area network (LAN), you often need to modify configuration files or set up an SSH tunnel. The dsh-web-lan plugin wraps the Web server’s request handling and provides a solution that requires no additional configuration. It treats LAN traffic as loopback access and adds a password login gate to control access permissions.

Plugin Overview

dsh-web-lan is a LAN access layer plugin for the DSH Web service, maintained by the developer yes8080. It addresses compatibility issues in pure HTTP LAN environments, provides a password-authenticated entry point, and supports managing the access password directly from the settings page.

Core Features

  1. crypto.randomUUID patch: Fixes API-layer failures caused by crypto.randomUUID is not a function in plaintext HTTP LAN environments.
  2. Password login gate: Unauthenticated requests can only see the login page. After successful authentication, the client obtains full permissions as a loopback identity, including access to Agent tools.
  3. Client isLoopback fix: The patch forces the browser-side isLoopback value to true, fixing the issue where the “Settings → Plugin Configuration” tab appears blank on pages accessed from a LAN.
  4. Password management: Supports modifying the password in the Web UI under “Settings → Plugins → Plugin Configuration” in the “LAN Access” card. Changes take effect immediately and are persisted to ~/.dsh/settings.yaml.

Installation and Activation

Run the following commands to install the plugin and restart the service:

dsh plugin --profile web add 'git+https://github.com/yes8080/dsh-web-lan.git'
npm exec @deepseek-ai/dsh web

After startup, the terminal prints the LAN access address, usually http://<ip>:3080.

Typical Usage

  1. Access and login: From another device on the LAN, visit http://<ip>:3080 and log in using the default password 123. It is recommended to change the password immediately after the first login.
  2. Set a password via environment variable: Before starting the service, run export DSH_LAN_PASSWORD='strong_password'.
  3. Manage it from the settings page: After logging in, go to the “Settings → Plugins → Plugin Configuration” card and change the password in the “LAN Access” section.

Security and Considerations

  • Default password risk: The default password 123 is weak and publicly known. Change it immediately after installation via the settings page or override it with an environment variable.
  • Transport: Passwords and data are transmitted over plaintext HTTP, so this is only suitable for trusted LAN environments.
  • Permission scope: A logged-in user has the same full permissions as a local user.
  • Runtime dependencies: This plugin requires pnpm. If pnpm is not enabled, run corepack enable pnpm first.

Uninstallation

To remove the plugin, run:

dsh plugin --profile web remove dsh-web-lan
npm exec @deepseek-ai/dsh web

After uninstallation, the service automatically reverts to listening on the default 127.0.0.1 address, and LAN access is disabled. You can optionally clean up residual data:

# 编辑 ~/.dsh/settings.yaml,删除 lan-access 段
rm ~/.dsh/dsh-lan-sessions.json

Conclusion

By using a plugin-based approach, dsh-web-lan simplifies LAN access for the DSH Web service, resolves compatibility defects, and adds a basic security gate. It is well suited for scenarios that require quick deployment and debugging of DSH applications within a local network.