Introduction

In agent development or everyday debugging, you often need to quickly share artifacts from a local workspace to a phone, tablet, or a colleague’s computer. Existing DSH plugin solutions each focus on different scenarios: dsh-lan-gate or dsh-plugin-remote-access proxy the DSH web interface and require sign-in or device approval for access; dsh-ssh targets remote server execution and SFTP; dsh-webfile connects to remote storage (such as S3 or FTP).

dsh-lan-share solves the problem of pure LAN HTTP sharing for files in the local workspace. It does not depend on an additional service, uses Node.js built-in modules, and lets devices on the same local area network directly browse, download, or upload files through a browser, without signing in to the DSH system.

Core Features

The plugin provides a complete set of file sharing capabilities:

  • HTTP sharing: Exposes the local workspace over HTTP, allowing direct access from browsers on phones, tablets, or other computers.
  • Zero dependencies: Uses only the built-in node:http module; no additional services need to be installed.
  • Security gate: Supports token-based access control to prevent unauthorized access. Fixed passwords can be configured, and each password can have an independently defined role (read-only/read-write) and expiration time.
  • Path boundaries: Prevents ../ path traversal attacks through path resolution.
  • Read-only mode: Can be enabled to restrict upload, delete, and move operations.
  • Rate limiting: Defaults to 120 requests per minute per IP; requests exceeding the limit receive a 429 status code.
  • Sensitive file hiding: Automatically filters directories and files such as .env, credential files (credentials.yaml, .netrc), keys (*.pem, *.key, *.pfx), node_modules, and .git.

Installation and Enablement

Add the following entry to the DeepSeek Harness configuration file (such as dsh.profile or cordis.yml):

plugins:
  - id: tool-lan-share
    name: 'dsh-lan-share'

Typical Usage

The plugin provides three core commands to control the sharing service.

1. Start Sharing

Run the lan_share_start command to start the service. You can specify the port, token, read-only mode, or subdirectory through parameters.

lan_share_start → {
  "ok": true,
  "running": true,
  "port": 3980,
  "root": "F:/work",
  "readOnly": false,
  "urls": ["http://192.168.1.5:3980/?token=9f2c...", "..."],
  "token": "9f2c..."
}

2. View Status

Use lan_share_status to view the runtime status, access addresses, token, and file statistics of the current sharing service.

3. Stop Sharing

Use lan_share_stop to stop the service.

4. Access and Operations

In a browser on any device on the local area network, enter the returned URL (with the token). In read/write mode, drag-and-drop upload and click-to-download are supported; in read-only mode, only browsing the directory tree and downloading files are supported.

5. Configuring Fixed Passwords

In addition to the random token generated at startup, fixed passwords can be configured. Pass a passwords array in lan_share_start:

lan_share_start → { passwords: [
  { password: "family", role: "read",  expiresIn: "3d" },
  { password: "admin",  role: "write", expiresIn: "long" },
] }

When accessing from a browser, pass the corresponding password via the URL parameter ?password= or the request header X-Password.

Configuration

You can configure parameters under the lan-share namespace in DSH settings:

lan-share:
  port: 3980            # 监听端口
  host: 0.0.0.0         # 监听地址,0.0.0.0 为全局域网,127.0.0.1 仅本机
  readOnly: false       # 默认只读模式
  rateLimitPerMin: 120  # 每 IP 限流(请求次数)
  hideSensitive: true   # 是否隐藏敏感文件

Notes

  • Node version requirement: The plugin requires Node.js version ^22.19.0 || >=24.0.0.
  • Code path: The core logic is located in src/lan-share-core.ts.
  • Access control default: By default, allowOpenAccess: false means access requires token or fixed password verification. If you need any device on the LAN to access without a password, you must manually enable this option.
  • Permission scope: The plugin runs with the permissions of the current DSH process. Ensure that read/write permissions for the relevant directories are properly configured.

Ecosystem Background

DeepSeek Harness (DSH) follows the “everything is a plugin” philosophy. dsh-lan-share is a community-maintained plugin; its directory page and GitHub repository can be found at the links below.