The design philosophy of DeepSeek Harness (DSH) is “everything is a plugin.” In web environments, developers often need to sync a desktop authentication session to a mobile device. Traditional approaches usually involve re-login or complex Token passing mechanisms. As a DSH Web plugin, dsh-qr-share provides a QR code generation entry directly at the bottom of the sidebar, aiming to reuse the authentication exchange flow already completed on the desktop.

Plugin Positioning

This plugin is maintained by user xiaoguomeiyitian and licensed under MIT. It is a DSH Web plugin whose core function is to provide a QR code button at the bottom of the sidebar, supporting mobile scanning and reuse of the completed ?token=… exchange on desktop, enabling same-session login.

Features

  1. Sidebar Entry: After logging in, a QR code icon appears at the bottom of the sidebar (next to the Settings button).
  2. Interaction Flow: Clicking the icon opens a dialog that displays the QR code and a plain-text URL (as a fallback if scanning fails).
  3. Automatic Adaptation: It automatically adapts to window.location.origin, pointing to the correct host without requiring additional environment variable configuration.
  4. Route Protection: The /_qr/share route is protected by connection.requestRejection, ensuring security.

Installation and Enablement

It is recommended to install it using the DSH plugin CLI:

dsh plugin --profile <name> add dsh-qr-share@latest

Configuration

After installation, add the configuration to the patch overlay. By default, enabled is true; set it to false to short-circuit the route to 404.

- insert:
    - id: qr-share
      name: 'dsh-qr-share'
      config:
        enabled: true

Usage Example

  1. Log in on the desktop and complete authentication.
  2. Click the QR code icon at the bottom of the sidebar.
  3. Scan the QR code or use the text URL with a phone.
  4. The server uses BrowserAuth to exchange the Token for a Cookie, redirects to /, and completes same-session login on the mobile device.

Technical Details

  • Token Lifecycle: The Token is valid only during a single dsh web activation and becomes invalid after the first exchange.
  • Cookie Security Policy: The Cookie is bound to a specific Authority and set to HttpOnly + SameSite=Strict.
  • Cross-Site Protection: SameSite=Strict + same-origin fetch ensure the route cannot be accessed from cross-site frames.
  • Dependency Requirements: Node >= 20, DSH >= 0.1.0-rc.8, React ^18 || ^19.

Use Cases and Notes

This plugin is suitable for scenarios requiring desktop-based development and quick synchronization of authentication state to mobile devices. The plugin runs with the permissions of the current dsh process; source code and license should be checked before installation.

Conclusion

dsh-qr-share simplifies session synchronization from desktop to mobile by reusing the Token exchange mechanism. For more details, see the community catalog or the GitHub repository.