Introduction

By default, the Web UI of DeepSeek Harness (dsh) has no login page and only allows access from loopback addresses. When exposing dsh to a LAN or other devices, direct access poses a security risk. This plugin places a password login gate in front of dsh and provides an HTTPS reverse proxy. It also fixes some known issues with cross-device access over a LAN.

Core Features

  • Password login: Supports a single-password scenario. The password file is stored in plaintext, and changes take effect immediately.
  • Self-signed HTTPS: Uses a self-signed certificate to encrypt traffic. Users can proceed after the browser warning (similar to the common NAS experience).
  • Protocol redirect: Accessing http via IP:port automatically redirects to https.
  • Session security: Uses an httpOnly cookie. Sessions are stored in memory and become invalid when the browser is closed.
  • Streaming capability: Fully forwards SSE / WebSocket, without affecting dsh’s real-time output and session list.
  • Dual protocol on one port: A single port handles both HTTP redirection and HTTPS service.
  • Zero dependencies: Depends only on the peer dependency @deepseek-ai/cordis, with no runtime npm dependencies.

Installation and Enablement

The installation process involves obtaining the plugin, registering the configuration, generating a certificate, and setting a password.

  1. Obtain the plugin
    Clone the repository locally, or download and unzip the zip archive.
    git clone https://github.com/Wayne036/dsh-plugin-login-gate.git
Place the plugin directory in a location accessible to dsh.
  1. Register in the profile
    Edit dsh’s cordis.patch.yml (for example, ~/.dsh/profiles/web/cordis.patch.yml) and append the configuration. If the plugin is not installed into node_modules, you can point name to the absolute path of the plugin directory.
    - insert:
        - id: login-gate
          name: 'dsh-plugin-login-gate'
          config:
            port: 3081
            passwordFile: 'C:/dsh/login-gate/password.txt'
            certFile: 'C:/dsh/login-gate/cert.pem'
            keyFile: 'C:/dsh/login-gate/key.pem'
            assetsDir: 'C:/dsh/login-gate/assets'
  1. Generate the certificate
    Use openssl to generate a self-signed certificate (valid for 10 years).
    openssl req -x509 -newkey rsa:2048 \
      -keyout key.pem -out cert.pem -days 3650 -nodes \
      -subj "/CN=DeepSeek-Harness-Login" \
      -addext "subjectAltName=IP:127.0.0.1,DNS:localhost,IP:<你的局域网IP>"
  1. Set the password
    Create a password file containing the login password (plaintext).
    echo '你的密码' > C:/dsh/login-gate/password.txt
  1. Configure pnpm-workspace (may be required when installing dependencies)
    If installing the node-pty dependency (dsh’s terminal capability) causes build scripts to be blocked, create or edit pnpm-workspace.yaml under the dsh profile directory to allow the build script.
    allowBuilds:
      node-pty: true
  1. Restart dsh
    Restart the dsh Web UI. Visit http://<IP>:<port> in a browser; it should automatically redirect to the HTTPS login page.

Configuration Items

Key Required Default Description
host No 0.0.0.0 Listening address
port No 3081 Entry port for the login gate
targetHost No 127.0.0.1 Forwarding target address
targetPort No 3080 dsh Web UI port
passwordFile Yes - Password file path (plaintext)
certFile Yes - TLS certificate PEM path
keyFile Yes - TLS private key PEM path
assetsDir No Built-in assets/ Login page assets directory
maxSessions No 64 Maximum number of concurrent login sessions
lanPatch No false Toggle for LAN cross-device access fixes

LAN Cross-Device Access Fixes

This plugin fixes three known issues that occur during LAN access.

BUG 1: HTTP 403 on the Model Configuration Page

Cause: dsh’s trust fence checks the Host / Origin request headers. If the reverse proxy forwards with a LAN address, the request is rejected.
Fix: The plugin automatically rewrites Host / Origin to loopback addresses at the proxy layer, without manual handling.

BUG 2: settings are unavailable on the Settings Page

Cause: The browser-side isLoopback check supports only localhost / 127.x, causing the settings page mirror to use memory persistence.
Fix: After enabling lanPatch, the plugin automatically applies a patch at startup, treating private network IP ranges as isLoopback. This patch only modifies client-side derived state and does not affect the server-side trust fence.

BUG 3: WebSocket Handshake Failure

Cause: When forwarding the WebSocket upgrade, the Upgrade / Connection headers are stripped, causing RFC 6455 validation to fail and preventing the event stream from being established.
Fix: The two headers are automatically restored before forwarding the 101 response.

Patch Notes

lanPatch is disabled by default. After enabling it, the plugin modifies internal files in dsh’s node_modules to apply the patch. The patch becomes invalid after updating or reinstalling dsh; run it again:

node node_modules/dsh-plugin-login-gate/patch-dsh-lan.js

Security Notes

  • Password storage: The password is stored in a local file in plaintext. Ensure that the file permissions allow only the current user to read and write it.
  • Certificate trust: Self-signed certificates are not trusted by browsers. Do not expose this endpoint to the public internet; use it only on a LAN/intranet.
  • Session management: Sessions are stored in memory. After dsh restarts, all devices must log in again.

Known Limitations

  • Single password only; no multi-user system.
  • No login failure lockout mechanism.
  • The self-signed certificate is valid for 10 years; it must be regenerated after expiration.
  • lanPatch modifies dsh source code; the patch must be reapplied after updating dsh.