When developing agents or using DeepSeek Harness (DSH), you may sometimes need to impersonate a specific client or bypass checks on target sites (such as a WAF). Editing configuration directly is cumbersome and may affect global behavior. The plugin provides a mechanism to inject request headers by domain, allowing you to modify HTTP request headers for specific hosts. Headers with the same name overwrite the original values.
Plugin Overview¶
The plugin is maintained by ZhiGangCai and is a request header injection tool. It supports injecting HTTP request headers based on host rules. Headers with the same name overwrite the original values, and header names are case-insensitive. The default configuration predefines one rule: inject User-Agent for agentrouter.org to bypass the WAF. The plugin is released under the MIT License.
How It Works¶
The plugin works by patching the global fetch function, so no changes to the DSH source code are required. It primarily targets the openai-completions and anthropic-messages pathways. When a request is sent, the system matches the host against rules in order and uses the first matching rule. After a match, it applies the set of request headers defined by the injection rule, overwriting same-name headers, and forwards the request. Requests that do not match any rule are passed through unchanged, with zero impact.
Installation and Enabling¶
Install the plugin via the command line. After installation, restart the DSH Web backend for the plugin to take effect.
dsh plugin --profile web add /path/to/dsh-header-injection
Configuration¶
1. Settings Panel (Recommended)¶
The DSH settings panel provides a visual configuration entry point and supports applying changes immediately.
- Go to DSH Settings -> Plugins -> Request Header Injection.
- Configuration options:
- enabled: Controls whether injection is enabled. Defaults totrue.
- rules: An array of injection rules. Each rule includeshosts(a list of hosts) andheaders(a set of request headers). - Rule format:
- Host: A comma-separated list of host suffixes. Subdomain matching is supported (for example,example.org, foo.commatchesa.example.organdfoo.com).
- Request headers: Multi-line text, with onename: valueentry per line. When injecting,Headers.setsemantics are used, meaning same-name headers are overwritten. - Shorthand form: Within a rule, you can use the
uafield instead of multi-line headers (for example,{hosts: "example.org", ua: "MyUA/1.0"}), which is equivalent to a singleUser-Agentheader. If both are present,headerstakes precedence.
After saving the configuration, the settings are persisted to the dsh-header-injection: section of ~/.dsh/settings.yaml and take effect without a restart.
2. Environment Variable Fallback¶
When the settings service is unavailable, environment variables can be used for configuration.
| Environment Variable | Default | Description |
|---|---|---|
AR_UA_ENABLED |
1 |
Stop injection while keeping the patch when 0 |
AR_UA_HOSTS |
agentrouter.org |
Comma-separated list of hosts |
AR_UA_VALUE |
RooCode/0.15.0 |
UA value |
AR_UA_RULES |
- | JSON array of multiple rules |
AR_UA_HEADERS |
- | Multi-line request header text (single-rule format) |
Usage¶
1. Status Summary¶
Use the dsh-header-injection command to view the current list of rules and the hit/rewrite counts.
dsh-header-injection
2. Health Check¶
Visit the HTTP health route GET /dsh-header-injection/health. This route returns the rules array and the hit/rewrite counts.
Typical Use Case: Bypassing the AgentRouter Client WAF¶
The AgentRouter frontend has deployed an Alibaba Cloud WAF, which performs triple verification on clients (TLS fingerprint + SDK request headers + request structure). The default User-Agent of DSH (deepseek-harness/<version>) is intercepted and returns unauthorized_client_error.
By injecting User-Agent: RooCode/0.15.0, the WAF allows the request to proceed to the token verification stage. Current testing shows that modifying only the UA is sufficient to bypass the fingerprint check, without needing to add extra headers such as X-Title or X-Stainless-*.
Notes¶
- Only injected headers are overwritten: The plugin only overwrites the injected request headers. Headers not mentioned in the rules remain unchanged.
- TLS fingerprint not spoofed: The current version does not spoof TLS fingerprints. Although
agentrouter.orgcurrently does not reject this UA combination based on fingerprints, if the target site tightens WAF checks, you need to add more headers to the rule. - Source code inspection: Before installing, inspect the source code and license to ensure they meet your environment requirements.
Ecosystem Context¶
The DSH philosophy is “everything is a plugin.” The community directory is an independent site and has no official affiliation with DeepSeek / Huanfang.
- Plugin Directory: https://www.skillhub.cn/plugins/ZhiGangCai/dsh-header-injection
- GitHub Repository: https://github.com/ZhiGangCai/dsh-header-injection