Introduction¶
DeepSeek Harness (DSH) uses a pluggable architecture. The default Web UI usually lacks enterprise-grade security protection. dsh-secure-gate is a plugin developed by xingjisen, designed to provide enterprise-grade security protection for the DeepSeek Harness Web UI. The plugin supports zero-configuration installation and becomes active after a restart.
Core Features¶
The plugin provides the following security capabilities:
- Password Security: Uses the Argon2id hashing algorithm and supports password strength enforcement and expiration policies.
- Two-Factor Authentication: Supports TOTP codes and backup recovery codes.
- Web Security: Provides CSRF protection, CSP headers, HSTS, and XFO (X-Frame-Options) protection.
- Access Control: Supports account lockout, permanent lockout, and IP allowlists/blocklists.
- Audit Monitoring: Records audit logs and manages sessions.
- Attack Protection: Supports rate limiting and exponential backoff policies.
Installation and Activation¶
Run the following command in a terminal to install the plugin:
dsh plugin --profile web add github:你的用户名/dsh-secure-gate
After installation, restart DSH. When you access the Harness Web UI in a browser, it automatically redirects you to the login page. On first access, you are guided to create an administrator account.
Notes¶
- The plugin runs with the permissions of the current DSH process.
- Before installing, review the source code and license (MIT © 2025).
- This plugin is a community project and has no official affiliation with DeepSeek or High-Flyer.
Conclusion¶
dsh-secure-gate provides comprehensive protection for DSH, covering passwords, authentication, and Web security. For more details, see the project directory page or the GitHub repository.