AI Agent Hub
Back to plugins
🖥️

dsh-secure-context-fix

Client Updated 2026.09.05

Run the following command in DeepSeek Harness:

dsh plugin install Li-Mingshuang/dsh-secure-context-fix

Paste the following prompt into your AI chat to install this plugin:

Run the install command in the DeepSeek Harness terminal; the plugin source is at https://github.com/Li-Mingshuang/dsh-secure-context-fix . Restart the profile after installation to activate the fix.

About this plugin

The DeepSeek Harness Web GUI calls crypto.randomUUID to mint RPC IDs, generate session and image-draft keys, and identify outgoing messages. Browsers only expose that API in secure contexts (HTTPS or localhost), so the moment you open the GUI from a phone or another device over plain HTTP on your LAN, every RPC throws: the workspace list never loads, the directory picker is dead, and new sessions cannot be created — while the same URL on 127.0.0.1 works perfectly.

This plugin registers a webServer.tapIndex transform. When the GUI serves index.html, the plugin injects a tiny inline script that installs a crypto.randomUUID implementation backed by crypto.getRandomValues() — an API browsers do expose on insecure origins — well before any dsh bundle code runs. No official source changes, no polyfill library, no build step for users. Install the plugin, restart your profile, and the GUI works from any LAN device.

It is ideal for anyone who uses dsh from a phone or tablet over a home or office LAN without HTTPS. Be aware that binding the GUI to 0.0.0.0 gives anyone who can reach the port remote-code-execution-level control of the agent; use it only on a trusted network and restrict the firewall rule to your LAN subnet. This plugin is a stop-gap for upstream discussion #4209 — if you can patch the three randomUUID call sites directly in the source, prefer that approach.

Use Cases

  • Opening the dsh Web GUI from a phone over home WiFi on plain HTTP causes the workspace list and directory picker to crash
  • Using a tablet in an office LAN to reach the dsh GUI — localhost works fine but every remote RPC throws
  • You do not want to set up HTTPS or patch dsh source code, and need a zero-friction fix so the Web GUI works on any LAN device

Best For

  • Users who open the dsh Web GUI from a phone or tablet over a LAN
  • Developers running dsh at home or in an office without HTTPS
  • Users who cannot or prefer not to patch upstream dsh source code and want a plugin-only fix