Introduction

DeepSeek Harness (DSH)’s desktop Web interface is bound to 127.0.0.1 by default, which helps secure sensitive capabilities such as terminal, files, and settings. In practice, however, developers often need to view sessions or continue conversations on mobile devices. Exposing ports directly creates security risks, while using a VPN adds configuration overhead.

The plugin described below runs a standalone HTTP listener inside the DSH process and provides a chat-only mobile entry point. It leaves the desktop Web surface unchanged while enabling access over the LAN or through a self-hosted tunnel.

What Is This

This is a DSH plugin maintained by huanlanmie. It is a PIN-protected mobile Web client that runs on a separate DSH port. It leverages DSH’s own services (such as sessionQuery and permissionPresets) to provide conversation capabilities, without modifying DSH’s core functionality.

Core Features

Mobile Client (/m/)

  • Login and Interface: Log in with an 8-digit PIN code; the interface includes a session list and a real-time conversation stream.
  • Streaming Responses and Tool Calls: Supports streaming output and inline rendering of tool-call steps.
  • In-session Actions: Switch models and permission presets without leaving the chat interface.
  • Statistics and Navigation: Displays session statistics consistent with the desktop interface (turns, tokens, cost), provides turn navigation, and supports paginated loading of history.
  • Themes: Supports switching between light and dark modes.

Desktop Settings Page

  • Global Control: Provides a master switch; when turned off, the listener does not start.
  • Network Configuration: Configure the listening port, network mode (LAN / Tunnel / Both), tunnel hostname, and idle timeout.
  • Session Management: Supports connecting a phone by scanning a QR code, revoking sessions, and viewing login history.

Security Features

  • Secure by Default: The plugin is disabled by default and listens only on the loopback address. It cannot be accessed externally before a PIN is set.
  • PIN Encryption: Stores the PIN using the scrypt algorithm (parameters N=2^14, r=8, p=1), with a random salt to help prevent brute-force attacks.
  • Token Management: Uses 256-bit random tokens, persistently stores their hashes, and enforces a 7-day expiration and an idle timeout (default 60 minutes).
  • Protection Mechanisms: Includes brute-force prevention (6 attempts per minute, IP lockout for 15 minutes after 5 failures, with escalating penalties), host allowlisting, and CSRF protection.

Installation and Enablement

Before installing, make sure your environment meets the requirements: Node.js ≥ 20 and DeepSeek Harness installed (version 0.1.1-rc.2 or higher).

Run the following command to install the plugin:

dsh plugin --profile web add github:huanlanmie/dsh-mobile-access

After installation, restart dsh web. A Mobile access option will appear in the settings cards of the desktop Web UI.

Typical Usage

  1. Set the PIN: Set an 8-digit PIN code in the Mobile access settings card in the desktop UI.
  2. Enable and configure the network: Turn on the master switch and select a network mode:
    • LAN: Listens on 0.0.0.0. If on the same Wi-Fi network, use a phone browser to scan the QR code on the settings page to access it.
    • Tunnel: Configure a tunnel service (such as Tailscale, cloudflared, or cpolar) and access it from the internet over HTTPS.
    • Both: Use LAN for local access and Tunnel for remote access.
  3. Use it on mobile: Open /m/ in a phone browser and enter the PIN code to continue a session.

Use Cases and Notes

  • LAN Mode Limitation: LAN mode uses plaintext HTTP. Any device on the network can sniff the PIN and session token. Do not use LAN mode on untrusted public Wi-Fi; prefer Tunnel mode.
  • Impact of PIN Reset: Changing or resetting the PIN revokes all existing sessions, requiring you to log in again.
  • Third-party Code: This plugin is a third-party open-source project and is not an official DeepSeek Harness component. It is recommended to review the source code before installing it in production environments.

By isolating mobile access from the desktop management interface, the plugin gives DSH users a convenient mobile option while maintaining security. For more details, refer to the GitHub repository.