Introduction¶
DSH follows a “everything is a plugin” architecture. During local development or deployment, if the dsh-web port is directly exposed, visitors can operate it without authentication. dsh-login is a purely host-side Cordis plugin that intercepts requests and validates sessions, providing full request gating for dsh-web.
Plugin Overview¶
- Name: dsh-login
- Owner: ravenli059
- Category: admin-security
- License: MIT
dsh-login adds a login gate to dsh-web: when opening the port, you must first enter a username and password. Account information is not stored in plaintext: passwords are hashed with scrypt (random salt), and the entire credentials file is encrypted with AES-256-GCM before being written to the local configuration file ($DSH_HOME/dsh-login.json, default ~/.dsh/dsh-login.json).
Core Features¶
- Full Request Gating
Wraps the webserver’sregister/registerUpgrade/registerFallback: SPA fallback,/apitransport, and WebSocket/SSE upgrades all go through session validation first. - Session Management
In-memory sessions +HttpOnly; SameSite=Strictcookies (default 24h, configurable). - Encrypted Storage
The credentials file is encrypted with AES-256-GCM; the key comes from theDSH_LOGIN_SECRETenvironment variable (64 hex characters or a passphrase) → key file$DSH_HOME/dsh-login.key(auto-generated). - Password Security
scrypt hashing with random salt (N=2^14, r=8, p=1); when a username does not exist, perform a dummy hash pass to prevent enumeration. - Brute-Force Protection
Sliding-window rate limiting per username+IP (default 5 attempts/30s → 429) + delay on failure. - Multi-User and CLI
Supports any number of accounts, and login is validated independently per username. Includes a standalone CLI (dsh-login) supporting commands such asstatus,set-user, andlist-users.
Installation and Enablement¶
Run the following commands in your local web profile:
# 1) Add this plugin to the web profile
dsh plugin --profile web add link:D:\code\dsh\dsh-login-plugin
# 2) Restart dsh web
# The next time you open http://127.0.0.1:3080 you will first see the login page; the first visit creates the administrator account.
The plugin is mounted via dsh.bundle.patch, and its dependency list has only three peers: cordis / dsh-host-webserver / schemastery.
Configuration¶
Add configuration to the plugin line in the user layer of the profile (after dsh plugin --profile web add, the dsh-login line is automatically inserted into the composition; to change the configuration, edit that dsh-login line in the - insert: section of ~/.dsh/profiles/web/cordis.patch.yml):
- id: dsh-login
config:
sessionTtlHours: 12 # Session TTL (hours), default 24
bootstrap: denied # Disable self-service account creation on the web; manage accounts only via CLI
maxAttempts: 10 # Brute-force rate limit: 10 attempts/30s
Key configuration options include enabled, storeFile, keyFile, sessionTtlHours, cookieName, bootstrap, and maxAttempts. Master key priority: DSH_LOGIN_SECRET environment variable → key file → plaintext mode (warning).
Typical Usage¶
After logging in, you can access /accounts to manage accounts (add, remove, rename, and change passwords from the web UI). The CLI provides additional management capabilities:
# View status
dsh-login status
# Create or reset a user
dsh-login set-user --user admin
# List all users
dsh-login list-users
Account changes made while running are hot-loaded via mtime polling.
Deployment and Security Notes¶
- Purely host-side plugin: It does not modify any dsh source code.
- Network binding: By default, it binds only to 127.0.0.1.
- LAN/public deployment: You need to set up an nginx service yourself and map the service for use within the LAN; it is recommended to add a TLS reverse proxy and set a strong passphrase.
- Key security: The
DSH_LOGIN_SECRETenvironment variable is used for master key derivation; configuring it is recommended.
Directory and Links¶
- Directory page: https://www.skillhub.cn/plugins/ravenli059/dsh-login
- GitHub repository: https://github.com/ravenli059/dsh-login