Introduction

By default, the Web GUI of DeepSeek Harness does not have username/password protection. If the web interface needs to be used in a multi-user collaboration or public environment, login authentication must be implemented yourself. WebGate is a plugin that adds a username/password gate to the DeepSeek Harness Web GUI. It protects the web interface through a route-level login gate and ensures that only authorized users can access it.

Core Features

WebGate provides the following capabilities:
* Route-level login gate: Every time the web interface is opened, login is required first. If there is no token or the token has expired, the page redirects to the login page automatically.
* 12-hour session token: After login, the token is valid for 12 hours. When it expires, the session logs out automatically.
* Zero interference with background tasks: The gate applies only to the browser view layer. Host-side background tasks, sessions, and sub-agents continue to run as normal.
* DeepSeek official-site-style login page: Provides a login interface consistent with the style of the DeepSeek official website.
* Graphical management on the settings page: Add or remove users, change passwords, and assign workspaces on the “WebGate Users” page in DSH settings.
* Protected built-in admin: The built-in admin account is a permanent administrator and cannot be deleted.
* User management commands: Provides command-line tools such as /useradd and /passwd for user management.
* Persistence: User data is stored in $DSH_HOME/.credentials.yaml and managed together with the Harness credential file.
* Trilingual support: Supports Chinese, English, and Русский, following the DSH language setting.
* Account roles and workspace authorization: Supports admin/member roles. Members can only view authorized workspaces.
* Zero dependencies: Implemented in pure JavaScript with no external dependencies.

Installation and Activation

Install the plugin via npm (recommended):

dsh plugin --profile web add @yyyq0325/dsh-webgate

The installation command mounts the plugin automatically based on its configuration. It takes effect after restarting dsh.

Initial Activation and Basic Usage

After the plugin is installed and dsh is restarted, the first access to the web interface automatically creates the initial administrator account.

  • Default account: username admin, password admin1234.
  • Change password:
    /passwd admin 你的新密码
  • Add a user:
    /useradd <用户名> <密码> <管理员密码>

Settings Page Management

In addition to the command line, WebGate provides a graphical interface for managing users.

  1. Open Settings in the lower-left corner.
  2. Go to the WebGate Users page.
  3. On this page, you can:
    • Add a user: Enter the username and password, select the role (member by default), and save.
    • Manage workspaces: Select the workspaces visible to the member (or select all).
    • Change password / delete user: Inline actions.
    • Note: The built-in admin administrator account does not have a delete button, and at least one administrator account must be retained.

Important Notes

  • Password storage: Passwords are stored as hashes in the webgate/users section of $DSH_HOME/.credentials.yaml.
  • Dynamic plugin mode: If you use dynamic plugin mode (non-persistent installation), only the Host side is included, and the settings page is unavailable. Users can only be managed via the command line.
  • Workspace filtering strength: Workspace filtering is executed in the browser. It is positioned as protection against accidental clicks rather than a defense against intentional bypass; the server side must still handle authentication itself.
  • Role restrictions: After a member logs in, only authorized workspaces are visible, and some UI actions (such as the settings entry and workspace creation) are hidden.

Summary

WebGate provides basic username/password protection and user management capabilities for the DeepSeek Harness Web GUI. It supports both command-line and graphical management and is suitable for scenarios that require using the Harness web interface in a multi-user environment.

View Catalog Page
GitHub Repository