dsh-web-auth
Run the following command in DeepSeek Harness:
dsh plugin install ChinaBoy0618/dsh-web-auth
Paste the following prompt into your AI chat to install this plugin:
Run dsh plugin install ChinaBoy0618/dsh-web-auth in DeepSeek Harness (source: https://github.com/ChinaBoy0618/dsh-web-auth), place the package into the profile node_modules, append dsh-web-auth to dsh.profile.bundles, generate a token, and point frp at the gatePort to enable the auth gate.
About this plugin
DSH Web binds to 127.0.0.1 by default and enforces a Host-trust fence on /api that rejects any non-loopback source outright, guarding against DNS-rebinding and cross-origin abuse. Requests arriving through an frp, ngrok, or similar tunnel are therefore blocked with a blanket 403, and DSH itself ships no login or password layer for external visitors. Slapping on a --trusted-host flag only pries open a crack in the fence; it is not authentication. dsh-web-auth exists to merge the fence and the credential check into a single, architecturally correct loopback reverse-proxy gate.
The plugin spawns a gate inside the DSH process (default 127.0.0.1:3081); point your frp tunnel at that port and you are ready. Browsers without a session are 302-redirected to a token login page; on success an HttpOnly session cookie is set (12-hour TTL, sliding renewal). Unauthenticated API calls, static assets, and WebSocket upgrades all receive a 401. For curl and scripting workloads, the X-DSH-Auth request header carries the token directly, bypassing the cookie flow entirely. Ten consecutive failed attempts from the same IP trigger a 10-minute rate-limit window, throttling brute-force guessing. Token resolution follows a strict priority chain of plugin config, environment variable, and a file under $DSH_HOME; if nothing is found the gate refuses to start (fail closed), leaving no unprotected public entry behind. Zero external dependencies - only Node.js built-in modules.
Best suited for developers who expose DSH Web over a tunnel and need a lightweight auth layer without writing login logic from scratch, as well as CI pipelines and automation scripts that prefer header-based token authentication over cookie handling.
Use Cases
- Exposing DSH Web to the public internet via frp or ngrok with token-based login
- Calling the DSH API from curl or scripts using the X-DSH-Auth header
- Throttling brute-force attempts with per-IP rate limiting on consecutive failures
Best For
- Developers exposing DSH Web over a tunnel who need a lightweight auth layer
- Teams that want a protected public entrypoint without writing login logic from scratch
- CI and automation authors calling the DSH API via header-based token auth
Related Plugins
A service-oriented sidebar framework for DSH, offering a full workbench with file explorer, embedded browser, real terminal, Git panel, and extensible plugin services.
A beautiful, practical Claude Code-style TUI plugin with pixel whale top bar, flowing glow title, real-time status line, streaming thought expansion, time rewind, context progress bar and TPS gauge — zero core changes.
The plugin market for DeepSeek Harness: browse/search/one-click install community plugins and themes, with updates, backup/restore, hot disable, diagnostics, and AI fix.
A persistent whale widget on the DSH web UI that shows DeepSeek balance, today's usage, and per-turn cost, with drag-and-snap and sound effects.