DSH Plugins
返回列表
🧩

dsh-auth

admin-security 更新于 2026.08.25

在终端中运行以下命令:

dsh plugin install optttt/dsh-auth

将以下提示词粘贴到 DeepSeek Harness 对话框中:

在 DeepSeek Harness 终端中运行 dsh plugin install optttt/dsh-auth 即可安装该插件,完整源码仓库地址为 https://github.com/optttt/dsh-auth,安装完成后重启 dsh web 即可生效。

插件介绍

The DeepSeek Harness web UI is feature-rich but ships with no access control by default. Anyone who discovers the port can read settings, manage files, or invoke plugins. dsh-auth closes that gap by placing a username-and-password gate in front of every HTTP, API, and WebSocket connection, so a self-hosted instance is no longer left wide open on a local network.

Once you hit the login page, you get a practical suite of session controls: a configurable idle-timeout auto-logout, a maximum session lifetime tunable in minutes, and a single-sign-on mode where every new login instantly invalidates all other sessions, dropping kicked clients back at the login screen with a clear warning. Passwords are stored as scrypt salted hashes, encrypted at rest with AES-256-GCM, with zero runtime dependencies. Under Settings > Auth you can change the username and password, adjust timeout values, and review the last 50 login events including IP, timestamp, and GeoIP location; one-liner CLI shortcuts make credential resets effortless.

A detail that matters in real deployments is the built-in LAN reverse proxy: dsh itself stays bound to 127.0.0.1, while the plugin listens on 0.0.0.0 (default port 3080), correctly forwarding WebSocket upgrade frames and rewriting Host/Origin headers so every /api RPC works out of the box for LAN clients. The UI follows the client language and adapts to light/dark themes automatically. If you run DeepSeek Harness on a local network and want to share the web admin panel with your team without exposing it to the open internet, dsh-auth is the lightest path to a properly gated instance.

使用场景

  • 在家庭或办公室局域网内安全共享 dsh web 管理界面
  • 为自建 DeepSeek Harness 实例添加用户名密码登录门槛
  • 在多个团队成员共用一台服务器时通过单点登录防止会话冲突

适合人员

  • 自建 DeepSeek Harness 并希望通过内网共享 Web 界面的个人开发者
  • 需要为本地管理面板增加基础认证的安全敏感型用户
  • 在小团队中多人共用 dsh web 的管理员