dsh-rgate
在终端中运行以下命令:
dsh plugin install raomaiping-hash/dsh-rgate
将以下提示词粘贴到 DeepSeek Harness 对话框中:
在 DeepSeek Harness 中执行 dsh plugin install raomaiping-hash/dsh-rgate 即可安装,源码地址:https://github.com/raomaiping-hash/dsh-rgate
插件介绍
The Harness's built-in trustedHosts fence is a DNS-rebinding defense, not an authentication layer. If you expose the Web UI over Tailscale, a LAN, or a public domain, anyone whose Host header clears the fence can drive your agent directly. dsh-rgate adds the missing authentication in front of the entire browser surface.
The plugin injects a gate script into every index.html so that anonymous non-loopback visitors land on a self-contained login page. At the same time it shadows all 52 unary RPC routes plus respond and session.export, returning a 401 before the request body is even parsed unless a valid session cookie is present. Passwords are stored as scrypt hashes with a random salt and constant-time comparison; login is throttled with exponential backoff after five failures; audit events are written to the harness log; and a Settings panel exposes gate status, logout, and password change. Loopback addresses always bypass the wall, preserving the local admin path.
It is aimed at self-hosted users who expose the Harness beyond localhost for a solo developer or a small team of three or five: one password, one gate, no enterprise auth stack required. Local development is completely unaffected.
使用场景
- 将 Harness Web UI 暴露到局域网或公网时,需要一道密码墙挡住匿名访客和 IP 扫描器。
- 通过 Tailscale 或 Cloudflare Tunnel 远程访问 Harness,但不想为每个 API 调用引入完整 IAM 栈。
- 本地开发保持零摩擦,同时让所有非回环流量必须认证后才能触碰 /api 路由。
适合人员
- 自托管 DeepSeek Harness 的独立开发者或个人项目维护者。
- 需要远程访问 Web UI 的 2~5 人小团队,用单密码即可满足。
- 希望用 scrypt 哈希 + 审计日志获得基本安全基线,而不引入企业级认证服务的用户。