AI Agent Hub
Back to plugins
🖥️

dsh-web-auth

Client Updated 2026.09.10

Run the following command in DeepSeek Harness:

dsh plugin install ChinaBoy0618/dsh-web-auth

Paste the following prompt into your AI chat to install this plugin:

Run dsh plugin install ChinaBoy0618/dsh-web-auth in DeepSeek Harness (source: https://github.com/ChinaBoy0618/dsh-web-auth), place the package into the profile node_modules, append dsh-web-auth to dsh.profile.bundles, generate a token, and point frp at the gatePort to enable the auth gate.

About this plugin

DSH Web binds to 127.0.0.1 by default and enforces a Host-trust fence on /api that rejects any non-loopback source outright, guarding against DNS-rebinding and cross-origin abuse. Requests arriving through an frp, ngrok, or similar tunnel are therefore blocked with a blanket 403, and DSH itself ships no login or password layer for external visitors. Slapping on a --trusted-host flag only pries open a crack in the fence; it is not authentication. dsh-web-auth exists to merge the fence and the credential check into a single, architecturally correct loopback reverse-proxy gate.

The plugin spawns a gate inside the DSH process (default 127.0.0.1:3081); point your frp tunnel at that port and you are ready. Browsers without a session are 302-redirected to a token login page; on success an HttpOnly session cookie is set (12-hour TTL, sliding renewal). Unauthenticated API calls, static assets, and WebSocket upgrades all receive a 401. For curl and scripting workloads, the X-DSH-Auth request header carries the token directly, bypassing the cookie flow entirely. Ten consecutive failed attempts from the same IP trigger a 10-minute rate-limit window, throttling brute-force guessing. Token resolution follows a strict priority chain of plugin config, environment variable, and a file under $DSH_HOME; if nothing is found the gate refuses to start (fail closed), leaving no unprotected public entry behind. Zero external dependencies - only Node.js built-in modules.

Best suited for developers who expose DSH Web over a tunnel and need a lightweight auth layer without writing login logic from scratch, as well as CI pipelines and automation scripts that prefer header-based token authentication over cookie handling.

Use Cases

  • Exposing DSH Web to the public internet via frp or ngrok with token-based login
  • Calling the DSH API from curl or scripts using the X-DSH-Auth header
  • Throttling brute-force attempts with per-IP rate limiting on consecutive failures

Best For

  • Developers exposing DSH Web over a tunnel who need a lightweight auth layer
  • Teams that want a protected public entrypoint without writing login logic from scratch
  • CI and automation authors calling the DSH API via header-based token auth