Preface

DeepSeek Harness (DSH)’s native workspace opener only supports loopback access. In DSH 0.1.2, file links call ctx.remote.session.openWorkspacePath({ path }); on remote pages, this native operation cannot open the desktop application on a remote device. This plugin solves the problem by wrapping the Remote method and opening the requested path in a GUI overlay backed by a path-whitelist HTTP endpoint. Loopback pages continue to use the native operating system opener.

Features

  1. Clicking a file link on a remote page opens a GUI overlay viewer (plain text, scrollable, selectable, editable, savable, touch-friendly).
  2. The “Files” handle on the left edge opens a directory browser (multi-root switcher, breadcrumbs, parent).
  3. Loopback pages retain native operating system open behavior.
  4. Encoding ladder: BOM (UTF-8 / UTF-16LE / UTF-16BE) → UTF-8 → GB18030; saving preserves the original encoding, BOM, and EOL style (CRLF/LF).
  5. Binary files: images (PNG/JPG/GIF/WebP/BMP) are displayed inline; other files show a prompt.
  6. Large files (> 2 MB) open in a read-only paged window.
  7. Atomic save (temporary file + rename).

Installation and Configuration

Use the insert directive to insert the plugin. inject: [webServer] ensures that the webServer is awaited before registering routes.

- insert:
    - id: fileview
      name: dsh-fileview
      inject: [webServer]
      config:
        roots:
          - 'D:\workspace'
          - 'C:\Users\me\projects'
        writeRoots:
          - 'D:\workspace'

A restart of dsh web is required after modifying composition or Host code. Changes to client-only client.js take effect only after rebuilding/reloading the client plugin.

Typical Usage

config.roots is a required read/write path whitelist (absolute directories; subpaths are allowed, and everything else returns 403). config.writeRoots optionally narrows the save scope to a subset.

Notes

This plugin is deprecated (2026-09-13). Since DSH 0.1.5, the built-in Web sidebar previews files (Markdown, code, HTML, PDF, and images) and displays files delivered by the model, replacing this plugin’s core use case. It is no longer maintained; the last targeted version is DSH 0.1.2.

Security design:
- Same-origin protection (Origin must match Host; callers without Origin follow the DSH API plane posture).
- Path whitelist (case-insensitive inclusion check; requests outside the root directories and traversal requests receive 403).
- Secure unconfigured state (no config.roots means no file routes are registered).
- Save limits (6 MB content limit; GBK/GB18030 files reject online saving because they cannot round-trip losslessly, so they open read-only).

References