DeepSeek Harness is essentially a local development tool that relies on 127.0.0.1 binding and request header validation by default. In Docker, reverse proxy, or public network deployment scenarios, this Host/Origin/Sec-Fetch-Site-based trust validation mechanism fails. The dsh-auth-gate plugin aims to mitigate the risk of unauthorized access in these scenarios and provide network-layer security protection for Harness.

Plugin Positioning

dsh-auth-gate is an authentication and security hardening plugin for DeepSeek Harness, maintained by zephaniahwang94-cmyk. It adds an authentication layer to HTTP and WebSocket routes to prevent unauthorized API access and impose restrictions on the approval process.

Core Features

The plugin provides the following capabilities:

  1. Bearer token + session login: Provides token-based authentication and session login for HTTP and WebSocket routes.
  2. Prepended per-session waterfall limiter: Adds a front-loaded limit to the watermark stream in the approval process to prevent approval overload.
  3. Fail-closed authentication gateway: When authentication configuration is enabled, requests that fail authentication are rejected directly (Fail-closed) instead of being allowed.

Installation and Enablement

The installation process automatically builds the plugin and registers it in the specified Harness configuration. Credentials are passed via environment variables and are not written to the configuration file.

Linux / macOS

export DSH_AUTH_USERNAME=admin
export DSH_AUTH_PASSWORD=Read-Host 'Enter a private password (12+ characters)'
./install.sh --protection Full

Windows PowerShell

$env:DSH_AUTH_USERNAME = 'admin'
$env:DSH_AUTH_PASSWORD = Read-Host 'Enter a private password (12+ characters)'
.\install.ps1 -Protection Full

After installation, subsequent Harness startups require specifying the patch file:

dsh --profile web --patch C:\path\to\dsh-auth-gate\presets\full.yml

Important Limitations and Notes

Before use, be aware of the following limitations:

  • No user isolation: All authenticated users share the same Agent instance and session pool, without user-level sandbox isolation.
  • No audit logs: The plugin does not log who authenticated or the specific user actions.
  • Does not fix ACP / SDK channels: These channels run via stdio (stdin/stdout), outside the HTTP network scope, and therefore are not protected by this plugin.
  • Validates headers, not network origin: The plugin validates request headers (such as Host/Origin) and does not validate the actual network origin of the request.
  • Reverse proxy login bucket: Login attempts are counted based on the TCP peer address. If deployed behind a reverse proxy (such as Nginx), users will share the proxy’s login bucket limit. In this case, it is recommended to configure rate limiting at the edge layer (reverse proxy), because the plugin cannot trust headers forwarded by the proxy.