The DSH Web settings page only recognizes the local machine address by default. When accessing it through a LAN IP address or a public domain name, the page will indicate that settings are unavailable. The dsh-loopback-bridge plugin injects logic into the client to make the browser believe that the current access address is a loopback address, thereby unlocking read/write permissions for the settings page.

Core Features

  • Remote settings modification: When opening DSH under a LAN IP, NAS domain, or public domain, the model and API Key in the settings page can be modified normally.
  • No changes to the official package: The plugin is installed independently and does not affect upgrades or maintenance of the official DSH package.
  • Effective after installation: After installation, restart the Web service to use it. No modifications to reverse proxy configurations such as Nginx are required.
  • 0.1.2-friendly: It has been adapted for DSH version 0.1.2, avoiding the Cookie validation issues caused by Host binding in older versions.

Installation and Enablement

  1. Ensure the server trusts the access address

    When starting dsh web, you must use the --trusted-host parameter to override the actual hostname or IP being accessed.

    dsh web --host 127.0.0.1 --port 3080 \
      --trusted-host 192.168.31.229 \
      --trusted-host dsh.example.com
  1. Install the plugin

    Use the official plugin installation command to add the plugin to the web profile.

    dsh plugin --profile web add github:johnhom1024/dsh-loopback-bridge
  1. Restart the service

    After installation, you need to restart dsh web. If deploying with Docker, it is recommended to rebuild the entire DSH stack rather than only restarting a single container.

    After installation and restart, refresh the page and open the settings page remotely. If the model tab no longer reports an error, you can save the API Key normally.

Version Requirements and Notes

  • Version compatibility:
    • Verified with DSH 0.1.2-rc.1.
    • For DSH 0.1.5 and later versions, you must use plugin version 1.0.1.
    • Early server versions require manual Host modification and are not recommended.
  • --trusted-host parameter: This is a prerequisite for enabling remote access and must match the actual address entered in the browser address bar.
  • Reverse proxy Host configuration: Do not rewrite the Host of privileged APIs to 127.0.0.1 (in version 0.1.2, Cookies are bound to the Host, and changing it will cause 401 authentication failures).
  • Authentication strategy:
    • A trusted LAN model can operate without additional authentication.
    • When exposed to the public internet, you must add an authentication layer in front, such as authentik or oauth2-proxy.

Security Model

This plugin only modifies client-side logic. This means that anyone who can open the DSH page can modify settings and call credentials.set. This behavior is expected behind a home reverse proxy; however, in a public internet environment, it must be used together with authentication components.

Summary

dsh-loopback-bridge solves the limited-functionality issue of the DSH Web UI in non-local access scenarios. By using client-side bridging technology, it allows developers to manage models and credentials from any address that can access the Web UI. If DSH officially supports disabling isLoopback detection at the server level, this plugin will become unnecessary, and can simply be uninstalled at that time.

  • GitHub: https://github.com/johnhom1024/dsh-loopback-bridge
  • Plugin Directory: https://www.skillhub.cn/plugins/johnhom1024/dsh-loopback-bridge