Introduction

When developing with the DeepSeek Harness (DSH) Web interface, the settings page usually contains multiple section navigation groups (such as General, Models, Plugins, etc.). When there are many sections, the navigation bar can become long, and frequently switching between sections requires multiple clicks.

The dsh-setting-manager plugin provides batch show/hide control for settings section navigation through a right-click menu. It does not modify rendering logic; it only hides sections using display:none, and persists the visibility state to a local file for reuse across different browser sessions.

Features

Right-click selection menu

Right-clicking anywhere on the section navigation on the left side of the settings page (including the title area) opens an overlay menu. The menu lists all settings sections in order, with a check mark on each row. Clicking a row immediately toggles the visibility state of that section and saves automatically. The menu closes when clicking an external area or pressing the Escape key.

Batch operations and hints

The bottom of the menu provides two buttons, “Show All” and “Hide All”, for batch control of section states. The menu does not close after clicking. If there are no visible sections in the navigation, the menu immediately displays a centered hint (using the DSH warning color) to inform the user that all sections are currently hidden. The hint disappears after any section is restored.

Cross-browser persistence

The plugin’s visibility state is not kept in memory; it is written to disk at $DSH_HOME/dsh-setting-manager.json. This means if a section is hidden in browser A, its hidden state remains in browser B or after the page is refreshed. The host side is responsible for reading and writing the state file.

Theme and automatic adaptation

The overlay menu style fully follows DSH theme variables (such as --dsw-alias-*, --dsw-font-family, --dsw-elevation-*), and automatically switches between light and dark themes. In addition, when sections are added or removed inside DSH or when the language changes, the plugin automatically rematches the labels and reapplies the previous hidden state.

Host-side API and security

The plugin registers the /api/setting-manager endpoint on the host side, providing GET and POST methods for reading and writing state. All responses include security headers (such as cache-control: no-store, x-content-type-options: nosniff, etc.). Requests are strictly validated: only Loopback access (127.0.0.1, ::1) is allowed; cross-site requests (sec-fetch-site: cross-site) are disallowed; invalid JSON or oversized request bodies (more than 16 KB returns 413) are rejected; DNS rebinding attacks are prevented.

Installation and Enabling

The plugin is installed through the DSH package manager and is installed to the current profile by default. Run the following command to complete the installation:

dsh plugin --profile web add github:coderHeJiyu/dsh-setting-manager

Usage

  1. Open the DSH web GUI and go to the settings page.
  2. Right-click anywhere on the section navigation bar on the left.
  3. Click a row in the popped-up menu to toggle section visibility, or click the buttons at the bottom for batch operations.
  4. Refresh the page or switch to another browser; the previous visibility settings are loaded automatically.

Technical Details

State file structure

The state file is located at $DSH_HOME/dsh-setting-manager.json ($DSH_HOME defaults to ~/.dsh).

{
  "version": 1,
  "hidden": [
    "models"
  ]
}
  • hidden: an array storing the IDs of hidden sections (corresponding to options.id in settings.section).
  • Fault-tolerance mechanism: if the file does not exist, parsing fails, or the format is invalid, the system automatically falls back to the default state { "version": 1, "hidden": [] }.
  • Write method: atomic writing is used; data is first written to a .tmp file and then renamed to overwrite the target file, preventing file corruption.

API endpoint

The host side registers the /api/setting-manager route under the webServer.

GET request: get the current state.
POST request: update the current state.
- Request body format: { "hidden": ["section-id"] }
- An empty request body {} is treated as clearing the hidden list.

Security validation rules

The plugin enforces strict request validation through host-side logic:
- Non-Loopback access: if the IP is outside the 127.0.0.0/8 or ::1 range, return 403.
- Host header validation: if the Host header is not a Loopback hostname, return 403.
- CORS validation: if Origin is missing or does not match the current origin, return 403.
- Content validation: invalid JSON or Content-Length exceeding the limit (16 KB) returns 400 or 413.
- Response headers: all responses include no-store, nosniff, same-origin, and no-referrer security headers.

Limitations and Dependencies

Functional scope

  • The plugin only controls the display of section navigation in settings.section; it does not affect child controls inside the settings page.
  • Triggering the right-click menu depends on matching the text of navigation buttons with section labels (based on multiset comparison). Custom sections or missing labels may not be recognized.

Dependency notes

  • The plugin depends on the built-in DSH dependencies @deepseek-ai/dsh-home-paths and @deepseek-ai/dsh-host-webserver.
  • @deepseek-ai/cordis is an optional dependency provided by the host.

Cross-profile sharing

The state file is globally unique and is not separated by profile. If the plugin is installed across multiple profiles, those profiles share the same visibility list.

Conclusion

dsh-setting-manager solves the cumbersome navigation caused by too many sections on the settings page. It provides a VS Code “Hide View”-like experience through a lightweight right-click menu and a persistence mechanism, while maintaining host-side security. The project is hosted on GitHub and is licensed under MIT.