DSH (DeepSeek Harness) is usually bound to 127.0.0.1 only, which restricts access to the local machine. To view the DSH Web interface from other devices on the LAN (such as a phone or office computer), a reverse proxy is required. dsh-3301 is designed to solve this problem. It forwards DSH’s local port to http://<this-machine-ip>:3301, providing password protection, session authentication, and WebSocket support.

Core Features

  • LAN access to DSH: Exposes the DSH Web interface to the local network.
  • Password-protected reverse proxy: Supports HTTP and WebSocket, preventing unauthorized access.
  • DSH plugin support: Integrated as a plugin into the DSH process, starting and stopping with DSH without requiring a separate daemon.
  • Session Cookie authentication: Uses a signed cookie after login (default validity: 30 days), avoiding frequent interruption of WebSocket connections by Basic Auth.
  • Rate limiting: Prevents brute-force attacks.
  • Cross-platform support: Based on built-in Node.js modules, supports Windows, macOS, and Linux.
  • Zero installation dependencies: Does not depend on external npm packages.

Installation and Deployment

This project does not currently publish an npm package and must be cloned and deployed via Git. Please ensure Node.js 18 or higher is installed.

  1. Clone the repository and enter the directory:
    git clone https://github.com/Aztech-Lab/dsh-3301
    cd dsh-3301
  1. Run the deployment script:
    node tools/deploy.mjs dsh-3301
The script writes the plugin files into DSH's configuration directory (usually `$DSH_HOME/profiles/<profile>`). If a permission-denied error occurs, check the directory permissions or run it as the owner.

Configuration and Usage

Plugin Configuration

After restarting DSH, navigate in the interface to Settings -> Plugins -> Plugin Configuration -> dsh-3301.

Setting Description
Enabled When enabled, listens on the specified port; when disabled, releases the port.
Bind Host 0.0.0.0 allows LAN access; 127.0.0.1 restricts access to the local machine only.
Port Defaults to 3301.
Username Username for the login form; defaults to dsh.
Session Lifetime The session cookie lifetime; defaults to 30 days.
Lockout Lockout policy for an IP after multiple failed login attempts.
Password Write-only input field. Leaving it empty clears the password; changing the password requires the old password.

Access Endpoint

After configuring and saving, access it from any device on the LAN:
http://<host-ip>:3301

For initial setup or password reset, access the initialization/setup page:
http://127.0.0.1:3301/__gate/setup

Check the service status (no authentication required):
http://127.0.0.1:3301/__gate/health

Notes

  • No password by default: The plugin starts without a default password. Any device that can reach port 3301 can access DSH. It is recommended to set a password before exposing it to the network.
  • Configuration method: All plugin settings are completed through the settings card; command-line arguments are not supported.
  • Style license: The plugin’s style code uses the BSD-3-Clause license.
  • Standalone mode: In addition to running as a plugin, the project still supports standalone CLI mode, configured via the DSH_PROXY_PASS environment variable.

Use Cases

Suitable for developers who need to use DSH over the LAN for agent development or debugging, especially in scenarios requiring long-lived WebSocket connections (such as SSE or real-time streaming output).