Introduction¶
Under the default security policy, the DeepSeek Harness (DSH) WebUI restricts access via non-localhost IP addresses (for example, LAN IP addresses). When accessed from a LAN, the Web UI disables settings, file upload, clipboard copying, and microphone permissions due to a missing secure context. dsh-lanmode is intended to remove these restrictions and provide secure LAN access, mDNS resolution, Root CA certificate generation, and PWA support for DSH.
Core Features¶
This plugin provides the following capabilities:
- LAN Access and mDNS: Enables access to the DSH WebUI through non-localhost IPs and provides mDNS resolution for
dsh.local, removing the need to memorize IP addresses. - Root CA and HTTPS: Generates a local Root CA certificate with a 10-year validity period and supports HTTPS access, unlocking browser security APIs such as WebRTC microphone access and clipboard access.
- PWA Support: Provides a Web App Manifest, allowing DSH to be installed on a mobile device home screen and run as a standalone app.
- QR Code Access: Generates a QR code containing a session token via the
/mobileqrcommand for quick mobile access by scanning. - Browser API Polyfills: Provides fallback implementations for
crypto.randomUUID,navigator.clipboard, andnavigator.mediaDevices.getUserMedia. - Loopback Hostname Bypass: Bypasses hostname checks so that settings and model pages remain available in LAN environments.
Installation and Dependencies¶
The provided source text does not include specific installation commands. Based on the project package.json information, this plugin has explicit dependency requirements:
Prerequisites
- DeepSeek Harness version: 0.1.7+
- Node.js version: 20+
Dependencies
The plugin depends on the following modules as Peer Dependencies:
- @deepseek-ai/cordis (^4.0.1)
- @deepseek-ai/dsh-host-webserver (^0.1.0-rc.6)
Typical Usage¶
In a DSH runtime environment, access the following endpoints via HTTP requests to configure or connect:
Generate an Access QR Code
GET /mobileqr
This command returns an SVG QR code containing the current LAN URL and session token. Scanning the code on a mobile device establishes the connection.
Install the Root Certificate
GET /dsh-lanmode/ca.crt
Download and install this certificate on a mobile device or browser to establish a trusted HTTPS connection, enabling voice input and clipboard functionality to work properly.
Check Health Status
GET /dsh-lanmode/health
Get the PWA Manifest
GET /dsh-lanmode/manifest.webmanifest
GET /dsh-lanmode/manifest.json
Applicable Scenarios and Notes¶
- Applicable Scenarios: Developers who need to use the DeepSeek Harness WebUI within a LAN, especially for mobile voice interaction, file upload, or scenarios requiring clipboard functionality.
- Notes: This plugin runs with the permissions of the current DSH process. Before installation, it is recommended to review the plugin’s source code and license (MIT) to ensure it meets your environment’s security requirements.
Summary¶
dsh-lanmode is a practical patch for DeepSeek Harness in LAN environments. Through non-intrusive HTML injection and a Root CA mechanism, it resolves functionality gaps in the WebUI when running in non-secure contexts. It supports mDNS resolution, PWA installation, and QR code access, making it suitable for users who need local deployment and remote access.
- GitHub repository: https://github.com/GooDAnDReaDY/dsh-lanmode
- Plugin directory: https://www.skillhub.cn/plugins/GooDAnDReaDY/dsh-lanmode