Foreword¶
DeepSeek Harness (DSH) uses a plugin-based architecture, and its Web UI does not include an authentication mechanism by default. Exposing the Web UI directly on a LAN or over the public internet introduces security risks. The dsh-auth-gate plugin adds a login gate in front of the DSH Web UI, provides SVG image CAPTCHA and brute-force protection, and enforces validation through the Nginx auth_request interface.
Plugin Overview¶
- Name: dsh-auth-gate
- Positioning: An authentication gate plugin for the DSH Web UI, providing SVG image CAPTCHA and brute-force protection.
- Owner: jiang539
- Category: admin-security
Core Features¶
- SVG Image CAPTCHA: Single-use, automatically removes easily confused characters, and supports IP-based rate limiting.
- Brute-force protection: Supports dual-dimension rate limiting by IP and by account. An IP is locked when consecutive failures from the same IP reach the threshold; an account is locked when consecutive credential failures for any account reach the threshold (IP rotation is ineffective).
- Session management: Supports sliding expiration; the Token’s validity period is extended on each validation.
- Session-bound IP (optional): Binds the Token to the client IP at login time; using it from another IP immediately invalidates it.
- Single Active Session: Only one active session is allowed for the same account at a time; a new login invalidates the previous session.
- Password security: Passwords are stored using bcrypt hashes (permission 0600), and the password file is readable and writable only by the owner.
- Nginx auth_request support: Enforces authentication at the Nginx layer, so unauthenticated requests are blocked before reaching DSH.
Installation and Enabling¶
Install it via the plugin management command:
dsh plugin --profile web add dsh-auth-gate
After the plugin is installed, DSH automatically registers the /auth/* routes on startup. DSH listens only on 127.0.0.1 by default, so access must be placed behind a reverse proxy such as Nginx.
Note: The default credentials are public values (account admin, password admin123). On first login, the account name and password must be changed.
Typical Usage¶
The plugin provides standard /auth API endpoints and can be used with curl or Nginx:
# 获取验证码
curl http://127.0.0.1:3080/auth/captcha
# 登录
curl -X POST http://127.0.0.1:3080/auth/login \
-H "Content-Type: application/json" \
-d '{"username":"admin","password":"your-password","captcha":"abcd","uuid":"<uuid>"}'
# 校验 Token
curl -H "Authorization: Bearer <token>" http://127.0.0.1:3080/auth/verify
Security and Considerations¶
- Default credentials: Before first login, use the default account
admin/admin123; after login, the credentials must be changed. - Local listening: The DSH Web UI listens only on
127.0.0.1. Be sure to perform front-end authentication using Nginxauth_request; otherwise, the plugin cannot intercept requests. - Permission management: The password file permissions must be strictly limited to
0600. - Development environment: The
devCaptchaTextconfiguration option is limited to development environments and must not be enabled in production. - Network transmission: HTTP deployment on a LAN is unsafe. Use HTTPS for public deployments.
Summary¶
dsh-auth-gate provides complete authentication and protection capabilities for the DSH Web UI, making it suitable for scenarios where DeepSeek Harness is deployed over the public internet or in untrusted networks. By combining Nginx auth_request with the plugin’s built-in brute-force protection, security risks can be significantly reduced.