Introduction¶
By default, the Web UI of DeepSeek Harness (dsh) has no login page and only allows access from loopback addresses. When exposing dsh to a LAN or other devices, direct access poses a security risk. This plugin places a password login gate in front of dsh and provides an HTTPS reverse proxy. It also fixes some known issues with cross-device access over a LAN.
Core Features¶
- Password login: Supports a single-password scenario. The password file is stored in plaintext, and changes take effect immediately.
- Self-signed HTTPS: Uses a self-signed certificate to encrypt traffic. Users can proceed after the browser warning (similar to the common NAS experience).
- Protocol redirect: Accessing
httpviaIP:portautomatically redirects tohttps. - Session security: Uses an
httpOnlycookie. Sessions are stored in memory and become invalid when the browser is closed. - Streaming capability: Fully forwards SSE / WebSocket, without affecting dsh’s real-time output and session list.
- Dual protocol on one port: A single port handles both HTTP redirection and HTTPS service.
- Zero dependencies: Depends only on the peer dependency
@deepseek-ai/cordis, with no runtime npm dependencies.
Installation and Enablement¶
The installation process involves obtaining the plugin, registering the configuration, generating a certificate, and setting a password.
- Obtain the plugin
Clone the repository locally, or download and unzip the zip archive.
git clone https://github.com/Wayne036/dsh-plugin-login-gate.git
Place the plugin directory in a location accessible to dsh.
- Register in the profile
Edit dsh’scordis.patch.yml(for example,~/.dsh/profiles/web/cordis.patch.yml) and append the configuration. If the plugin is not installed intonode_modules, you can pointnameto the absolute path of the plugin directory.
- insert:
- id: login-gate
name: 'dsh-plugin-login-gate'
config:
port: 3081
passwordFile: 'C:/dsh/login-gate/password.txt'
certFile: 'C:/dsh/login-gate/cert.pem'
keyFile: 'C:/dsh/login-gate/key.pem'
assetsDir: 'C:/dsh/login-gate/assets'
- Generate the certificate
Use openssl to generate a self-signed certificate (valid for 10 years).
openssl req -x509 -newkey rsa:2048 \
-keyout key.pem -out cert.pem -days 3650 -nodes \
-subj "/CN=DeepSeek-Harness-Login" \
-addext "subjectAltName=IP:127.0.0.1,DNS:localhost,IP:<你的局域网IP>"
- Set the password
Create a password file containing the login password (plaintext).
echo '你的密码' > C:/dsh/login-gate/password.txt
- Configure pnpm-workspace (may be required when installing dependencies)
If installing thenode-ptydependency (dsh’s terminal capability) causes build scripts to be blocked, create or editpnpm-workspace.yamlunder the dsh profile directory to allow the build script.
allowBuilds:
node-pty: true
- Restart dsh
Restart the dsh Web UI. Visithttp://<IP>:<port>in a browser; it should automatically redirect to the HTTPS login page.
Configuration Items¶
| Key | Required | Default | Description |
|---|---|---|---|
host |
No | 0.0.0.0 |
Listening address |
port |
No | 3081 |
Entry port for the login gate |
targetHost |
No | 127.0.0.1 |
Forwarding target address |
targetPort |
No | 3080 |
dsh Web UI port |
passwordFile |
Yes | - | Password file path (plaintext) |
certFile |
Yes | - | TLS certificate PEM path |
keyFile |
Yes | - | TLS private key PEM path |
assetsDir |
No | Built-in assets/ |
Login page assets directory |
maxSessions |
No | 64 |
Maximum number of concurrent login sessions |
lanPatch |
No | false |
Toggle for LAN cross-device access fixes |
LAN Cross-Device Access Fixes¶
This plugin fixes three known issues that occur during LAN access.
BUG 1: HTTP 403 on the Model Configuration Page¶
Cause: dsh’s trust fence checks the Host / Origin request headers. If the reverse proxy forwards with a LAN address, the request is rejected.
Fix: The plugin automatically rewrites Host / Origin to loopback addresses at the proxy layer, without manual handling.
BUG 2: settings are unavailable on the Settings Page¶
Cause: The browser-side isLoopback check supports only localhost / 127.x, causing the settings page mirror to use memory persistence.
Fix: After enabling lanPatch, the plugin automatically applies a patch at startup, treating private network IP ranges as isLoopback. This patch only modifies client-side derived state and does not affect the server-side trust fence.
BUG 3: WebSocket Handshake Failure¶
Cause: When forwarding the WebSocket upgrade, the Upgrade / Connection headers are stripped, causing RFC 6455 validation to fail and preventing the event stream from being established.
Fix: The two headers are automatically restored before forwarding the 101 response.
Patch Notes¶
lanPatch is disabled by default. After enabling it, the plugin modifies internal files in dsh’s node_modules to apply the patch. The patch becomes invalid after updating or reinstalling dsh; run it again:
node node_modules/dsh-plugin-login-gate/patch-dsh-lan.js
Security Notes¶
- Password storage: The password is stored in a local file in plaintext. Ensure that the file permissions allow only the current user to read and write it.
- Certificate trust: Self-signed certificates are not trusted by browsers. Do not expose this endpoint to the public internet; use it only on a LAN/intranet.
- Session management: Sessions are stored in memory. After dsh restarts, all devices must log in again.
Known Limitations¶
- Single password only; no multi-user system.
- No login failure lockout mechanism.
- The self-signed certificate is valid for 10 years; it must be regenerated after expiration.
lanPatchmodifies dsh source code; the patch must be reapplied after updating dsh.