Introduction

DSH follows a “everything is a plugin” architecture. During local development or deployment, if the dsh-web port is directly exposed, visitors can operate it without authentication. dsh-login is a purely host-side Cordis plugin that intercepts requests and validates sessions, providing full request gating for dsh-web.

Plugin Overview

  • Name: dsh-login
  • Owner: ravenli059
  • Category: admin-security
  • License: MIT

dsh-login adds a login gate to dsh-web: when opening the port, you must first enter a username and password. Account information is not stored in plaintext: passwords are hashed with scrypt (random salt), and the entire credentials file is encrypted with AES-256-GCM before being written to the local configuration file ($DSH_HOME/dsh-login.json, default ~/.dsh/dsh-login.json).

Core Features

  1. Full Request Gating
    Wraps the webserver’s register / registerUpgrade / registerFallback: SPA fallback, /api transport, and WebSocket/SSE upgrades all go through session validation first.
  2. Session Management
    In-memory sessions + HttpOnly; SameSite=Strict cookies (default 24h, configurable).
  3. Encrypted Storage
    The credentials file is encrypted with AES-256-GCM; the key comes from the DSH_LOGIN_SECRET environment variable (64 hex characters or a passphrase) → key file $DSH_HOME/dsh-login.key (auto-generated).
  4. Password Security
    scrypt hashing with random salt (N=2^14, r=8, p=1); when a username does not exist, perform a dummy hash pass to prevent enumeration.
  5. Brute-Force Protection
    Sliding-window rate limiting per username+IP (default 5 attempts/30s → 429) + delay on failure.
  6. Multi-User and CLI
    Supports any number of accounts, and login is validated independently per username. Includes a standalone CLI (dsh-login) supporting commands such as status, set-user, and list-users.

Installation and Enablement

Run the following commands in your local web profile:

# 1) Add this plugin to the web profile
dsh plugin --profile web add link:D:\code\dsh\dsh-login-plugin

# 2) Restart dsh web
# The next time you open http://127.0.0.1:3080 you will first see the login page; the first visit creates the administrator account.

The plugin is mounted via dsh.bundle.patch, and its dependency list has only three peers: cordis / dsh-host-webserver / schemastery.

Configuration

Add configuration to the plugin line in the user layer of the profile (after dsh plugin --profile web add, the dsh-login line is automatically inserted into the composition; to change the configuration, edit that dsh-login line in the - insert: section of ~/.dsh/profiles/web/cordis.patch.yml):

- id: dsh-login
  config:
    sessionTtlHours: 12        # Session TTL (hours), default 24
    bootstrap: denied          # Disable self-service account creation on the web; manage accounts only via CLI
    maxAttempts: 10            # Brute-force rate limit: 10 attempts/30s

Key configuration options include enabled, storeFile, keyFile, sessionTtlHours, cookieName, bootstrap, and maxAttempts. Master key priority: DSH_LOGIN_SECRET environment variable → key file → plaintext mode (warning).

Typical Usage

After logging in, you can access /accounts to manage accounts (add, remove, rename, and change passwords from the web UI). The CLI provides additional management capabilities:

# View status
dsh-login status

# Create or reset a user
dsh-login set-user --user admin

# List all users
dsh-login list-users

Account changes made while running are hot-loaded via mtime polling.

Deployment and Security Notes

  1. Purely host-side plugin: It does not modify any dsh source code.
  2. Network binding: By default, it binds only to 127.0.0.1.
  3. LAN/public deployment: You need to set up an nginx service yourself and map the service for use within the LAN; it is recommended to add a TLS reverse proxy and set a strong passphrase.
  4. Key security: The DSH_LOGIN_SECRET environment variable is used for master key derivation; configuring it is recommended.
  • Directory page: https://www.skillhub.cn/plugins/ravenli059/dsh-login
  • GitHub repository: https://github.com/ravenli059/dsh-login