Introduction¶
The DeepSeek Harness web server is designed for security and only binds to 127.0.0.1, and using --host 0.0.0.0 is officially prohibited. This prevents developers from accessing the GUI directly from a LAN or a public network. The dsh-mobile-access plugin fills this gap by running a gateway proxy on the PC. It not only implements port forwarding, but also includes PC-side approval gating and automatic network environment detection to ensure secure mobile access.
Core Features¶
- PC-side approval gating: A mobile device’s first access must be approved from the PC. It supports approve, reject, revoke, restore, delete, and “revoke authorization and delete” operations.
- Automatic network environment detection: Automatically detects whether the access source is a local area network (LAN), VPN, or direct public network. When the network environment changes, the mobile client shows a prompt asking whether to switch modes.
- Secure external network access: For direct public network access, it recommends switching to Tailscale or ZeroTier. The PC panel can enable the “block public direct connections” policy to forcibly block devices coming from public IPs.
- Real-time status synchronization and forwarding: The PC-side “current session” is automatically synchronized to the mobile client, and real-time WebSocket forwarding is supported (
/api/events.mux,/api/events.host). - Mobile adaptation: Automatically adapts the UI for mobile devices, follows DSH theme tokens (supports dark/light and third-party skins), and automatically wraps the input toolbar and action area onto separate lines.
Installation and Activation¶
This plugin is a static plugin package and is loaded automatically when DSH starts. After installation, there is no need to redeploy it on every restart.
Run the following command to install it:
# 方式一:本地安装
dsh plugin --profile web add dsh-mobile-access
# 方式二:从 GitHub 安装(锁定版本 v1.0.5)
dsh plugin --profile web add dsh-mobile-access@github:TongaiLinC/dsh-mobile-access#v1.0.5
After installation, restart DSH. After a successful startup, a blue “📱” floating button will appear in the bottom-right corner of the PC page.
Usage Workflow¶
1. Start the Gateway (PC Side)¶
Click the “📱” button in the bottom-right corner to open the mobile access panel, then click “Start Gateway”.
The gateway listens on 0.0.0.0:3081 by default. If you are using Windows, please allow inbound connections for this port through the firewall on the first startup.
2. Access and Scan (Mobile Side)¶
- LAN access: Connect the phone to the same Wi-Fi, scan the QR code on the PC panel with the camera or WeChat, or enter
http://<PC LAN IP>:3081directly in the browser. - Public network access: It is recommended to establish a VPN tunnel with tools such as Tailscale or ZeroTier, then access it through the VPN address.
3. Initial Approval¶
The first access from the phone enters the approval gate page. After naming the device and submitting the request, the device will appear in the “Device Approval” area of the PC panel. After clicking “Approve”, the mobile client will automatically be allowed into the GUI within approximately 3 seconds.
4. Device and Policy Management (PC Side)¶
- Device management: In the PC panel, you can approve, reject, revoke, restore, or delete devices.
- Security policy: After enabling the “block public direct connections” policy, all device requests from public IP ranges are forcibly blocked and must use VPN access.
Notes¶
- Security risks: The gateway link does not have TLS encryption, so cookies and conversation content may be sniffed. It is strongly recommended to use an encrypted VPN (such as Tailscale/ZeroTier) rather than direct HTTP access.
- Identity authentication: The legacy public
x-dshm-admin: 1header has been deprecated, and any LAN device can spoof it. The new version usesx-dshm-admin-tokencombined with a loopback address check, ensuring that administrator privileges are limited to the local PC. - Data persistence: Device and policy data are stored in the
$DSH_HOME/dsh-mobile/state.jsonfile. - Firewall: Windows users must ensure that the firewall allows
node.exeto accept inbound connections on port 3081 (default).
Summary¶
This plugin solves the issue that the DSH Web GUI is bound only to the local machine. By using the PC as a relay gateway, it enables secure and controllable access from mobile devices. For users who need to switch between multiple devices or use a mobile device to develop agents, it provides a low-intrusion, feature-complete solution.