Preface¶
By default, the Web service of DeepSeek Harness (DSH) usually listens only to the local address. To access or debug it directly from other devices on a local area network (LAN), you often need to modify configuration files or set up an SSH tunnel. The dsh-web-lan plugin wraps the Web server’s request handling and provides a solution that requires no additional configuration. It treats LAN traffic as loopback access and adds a password login gate to control access permissions.
Plugin Overview¶
dsh-web-lan is a LAN access layer plugin for the DSH Web service, maintained by the developer yes8080. It addresses compatibility issues in pure HTTP LAN environments, provides a password-authenticated entry point, and supports managing the access password directly from the settings page.
Core Features¶
crypto.randomUUIDpatch: Fixes API-layer failures caused bycrypto.randomUUID is not a functionin plaintext HTTP LAN environments.- Password login gate: Unauthenticated requests can only see the login page. After successful authentication, the client obtains full permissions as a loopback identity, including access to Agent tools.
- Client
isLoopbackfix: The patch forces the browser-sideisLoopbackvalue totrue, fixing the issue where the “Settings → Plugin Configuration” tab appears blank on pages accessed from a LAN. - Password management: Supports modifying the password in the Web UI under “Settings → Plugins → Plugin Configuration” in the “LAN Access” card. Changes take effect immediately and are persisted to
~/.dsh/settings.yaml.
Installation and Activation¶
Run the following commands to install the plugin and restart the service:
dsh plugin --profile web add 'git+https://github.com/yes8080/dsh-web-lan.git'
npm exec @deepseek-ai/dsh web
After startup, the terminal prints the LAN access address, usually http://<ip>:3080.
Typical Usage¶
- Access and login: From another device on the LAN, visit
http://<ip>:3080and log in using the default password123. It is recommended to change the password immediately after the first login. - Set a password via environment variable: Before starting the service, run
export DSH_LAN_PASSWORD='strong_password'. - Manage it from the settings page: After logging in, go to the “Settings → Plugins → Plugin Configuration” card and change the password in the “LAN Access” section.
Security and Considerations¶
- Default password risk: The default password
123is weak and publicly known. Change it immediately after installation via the settings page or override it with an environment variable. - Transport: Passwords and data are transmitted over plaintext HTTP, so this is only suitable for trusted LAN environments.
- Permission scope: A logged-in user has the same full permissions as a local user.
- Runtime dependencies: This plugin requires
pnpm. Ifpnpmis not enabled, runcorepack enable pnpmfirst.
Uninstallation¶
To remove the plugin, run:
dsh plugin --profile web remove dsh-web-lan
npm exec @deepseek-ai/dsh web
After uninstallation, the service automatically reverts to listening on the default 127.0.0.1 address, and LAN access is disabled. You can optionally clean up residual data:
# 编辑 ~/.dsh/settings.yaml,删除 lan-access 段
rm ~/.dsh/dsh-lan-sessions.json
Conclusion¶
By using a plugin-based approach, dsh-web-lan simplifies LAN access for the DSH Web service, resolves compatibility defects, and adds a basic security gate. It is well suited for scenarios that require quick deployment and debugging of DSH applications within a local network.