Introduction

The DeepSeek Harness Web interface binds to a local address by default. To access it on a local network, you typically need to manually configure port forwarding or a reverse proxy. This plugin directly configures and manages the 0.0.0.0 WebServer LAN listening, trustedHosts trust boundary, and random launch token-based authentication flow that ship with DSH 0.1.5. It does not implement a second reverse proxy or custom storage; instead, it leverages DSH’s native WebServer and BrowserAuth mechanisms to provide a secure and persistent LAN access endpoint.

Core Capabilities

The plugin provides the following features:
1. Configure and display DSH 0.1.5’s built-in 0.0.0.0 WebServer LAN listening.
2. Manage the LAN IP trustedHosts trust boundary.
3. Authenticate using a per-process random launch token.
4. Issue an HttpOnly Cookie.
5. Set the authorized Cookie lifetime (default: 30 days).
6. Provide a one-click “Save and restart DSH” function.
7. Provide a complete token-based authorization link.

Installation and Enablement

Before installing, ensure DeepSeek Harness CLI 0.1.5-rc.1 and Node.js >=22.19.0 are installed.

git clone https://github.com/advance-lion/dsh-lan-link.git
cd dsh-lan-link
dsh plugin --profile web add .

After installation, go to Settings → Plugins → Plugin Configuration → LAN Link, enable the LAN access switch, and restart the process.

Usage Flow

After enabling LAN access and restarting DSH, the settings page generates an authorization link with a random token, formatted like http://IP:PORT/?token=....

  1. Open the generated link from a remote browser.
  2. DSH’s native BrowserAuth verifies the random token for that process.
  3. After verification succeeds, DSH returns a redirect and writes a signed Cookie bound to the hostname and port.
  4. After that, you can access the interface using a URL without the token. The Cookie is valid for 30 days by default.

If you change the binding address, port, or authorization duration, click the “Save and restart DSH” button to apply the changes.

Security and Notes

Dependency environment: The plugin depends on DeepSeek Harness CLI 0.1.5-rc.1 and Node.js >=22.19.0.

Restart mechanism: DSH 0.1.5’s WebServer and BrowserAuth read their configuration when the process starts. The listening address (such as 127.0.0.1 versus 0.0.0.0) and Cookie lifetime cannot be hot-switched, so a process restart is required after changing related settings.

Security attributes: The Cookie uses strict browser security attributes (HttpOnly, Host-only, SameSite=Strict) and is bound to the hostname and port. Changing the IP address or port requires re-authorization.

Network risks: Plain HTTP is not encrypted, and network sniffing is possible on a local network. Do not expose the port to the public internet or use public Wi-Fi. Restrict access to the local firewall’s “Private network” profile only.

Feature scope: The plugin does not implement a self-hosted HTTP/WebSocket proxy, nor does it store long-lived tokens. All permissions are equivalent to DSH’s native full-token authorization.