Introduction

DeepSeek Harness (DSH) uses a pluggable architecture. The default Web UI usually lacks enterprise-grade security protection. dsh-secure-gate is a plugin developed by xingjisen, designed to provide enterprise-grade security protection for the DeepSeek Harness Web UI. The plugin supports zero-configuration installation and becomes active after a restart.

Core Features

The plugin provides the following security capabilities:

  • Password Security: Uses the Argon2id hashing algorithm and supports password strength enforcement and expiration policies.
  • Two-Factor Authentication: Supports TOTP codes and backup recovery codes.
  • Web Security: Provides CSRF protection, CSP headers, HSTS, and XFO (X-Frame-Options) protection.
  • Access Control: Supports account lockout, permanent lockout, and IP allowlists/blocklists.
  • Audit Monitoring: Records audit logs and manages sessions.
  • Attack Protection: Supports rate limiting and exponential backoff policies.

Installation and Activation

Run the following command in a terminal to install the plugin:

dsh plugin --profile web add github:你的用户名/dsh-secure-gate

After installation, restart DSH. When you access the Harness Web UI in a browser, it automatically redirects you to the login page. On first access, you are guided to create an administrator account.

Notes

  1. The plugin runs with the permissions of the current DSH process.
  2. Before installing, review the source code and license (MIT © 2025).
  3. This plugin is a community project and has no official affiliation with DeepSeek or High-Flyer.

Conclusion

dsh-secure-gate provides comprehensive protection for DSH, covering passwords, authentication, and Web security. For more details, see the project directory page or the GitHub repository.