Introduction

DeepSeek Harness (DSH) is a command-line tool for agent development. When you need to expose a Web UI panel to your team or deploy it to the public internet, you usually need a login layer in front. The dsh-ui-auth plugin intercepts DSH’s HTTP and WebSocket channels and redirects unauthenticated users to a login page, establishing a security gate before DSH route dispatch.

Plugin Positioning

This is a DSH Web UI authentication gateway plugin. It is maintained by 0QwQ0. It provides a login page, user management, TOTP/passkeys, administrator model configuration, and data isolation.

Core Features

  • Full-interface interception: Covers HTTP and WebSocket. When a user is not logged in, access is blocked, API responses return 401, and page requests are redirected to the login page.
  • Login and registration: The interface is in Chinese, and registration requires an invitation code generated by an administrator.
  • User management: Supports password changes, TOTP binding, and passkey management.
  • Permission isolation: Regular users can only see their own sessions and workspaces; administrators are unrestricted.
  • Security protection: Passwords are encrypted with PBKDF2, and a login failure lockout mechanism is supported.

Installation and Enablement

Use the standard DSH profile bundle installation method:

dsh plugin --profile web add dsh-ui-auth

After installation, restart the DSH panel for the gateway and settings panel to take effect.

First Login

When the plugin is enabled for the first time, it automatically creates the administrator account admin. The random password is output to the console log (prefixed with [dsh-ui-auth]) and to dsh-ui-auth-bootstrap.txt under the panel working directory. After logging in with this account, immediately change the password in Settings → User Management.

Usage Notes

  • Registration: New user registration requires an invitation code generated by an administrator in User Management.
  • Passkeys: WebAuthn passkey functionality requires an HTTPS or localhost environment.
  • Environment variables: You can set DSH_AUTH_MAX_FAILS to adjust the lockout threshold for consecutive login failures per IP.

Compatibility and Notes

  • Compatibility: Supports DSH 0.1.1-rc.2 or 0.1.2-rc.1 ~ 0.1.5-rc.1.
  • Security policy: Passwords must be at least 8 characters long and include two character types; private keys are not stored on the server.
  • Limitations: The last administrator cannot be deleted or demoted; private keys never leave the user device.

Background and Ecosystem

DSH’s philosophy is “everything is a plugin.” This plugin is a community-maintained project and has no official affiliation with DeepSeek / High-Flyer. See the project homepage for more details.