dsh-web-pass
在终端中运行以下命令:
dsh plugin install linz919/dsh-web-pass
将以下提示词粘贴到 DeepSeek Harness 对话框中:
在 DeepSeek Harness 中执行 dsh plugin install linz919/dsh-web-pass 即可安装该插件,源码仓库为 https://github.com/linz919/dsh-web-pass
插件介绍
Once a DeepSeek Harness web interface is reachable via a LAN IP or a public domain, it lacks a dedicated password gate of its own. DSH's built-in browser authentication requires visitors to juggle tokens and cookies, and the settings pages go blank when the URL is not loopback. dsh-web-pass runs a zero-dependency reverse proxy inside the DSH process, overlays cookie-based password authentication on top, and automatically acquires and injects DSH's persistent cookie so that visitors only ever face one password prompt while DSH's internal auth stays completely transparent.
Key capabilities include: a forced initial password setup, automatic temporary lockout after repeated failures, a built-in /dsh-logs/ viewer that records only password-verification requests with visitor IPs pseudonymized via HMAC-SHA256 plus a network prefix, size-based log rotation with a hard total-size cap, and full settings-page availability when accessed through a non-loopback address. The plugin also adds a dedicated Web Password tab in the DSH settings for changing the access password and logging out.
It is aimed at teams or individuals who want to share a DSH instance over a LAN or the public web without adding nginx Basic Auth, who need a lightweight yet auditable access gate that never exposes real visitor IPs, and who want a simple shared-password model without a full account directory. All runtime data lives under $DSH_HOME/dsh-web-pass/, keeping the plugin repository itself free of sensitive material.
使用场景
- 在局域网内共享 DSH 实例,避免部署 nginx Basic Auth 或独立身份系统
- 通过公网域名或隧道暴露 DSH,用一道密码门保护入口并自动代持内置认证
- 审计 DSH 访问记录,同时用 HMAC 假名化保护访客真实 IP 不被明文留存
适合人员
- 需要在小团队内网共享 DSH 但不想引入账号体系的运维或开发者
- 通过 Cloudflare 隧道、VPS 公网映射等方式对外暴露 DSH 的个人用户
- 重视访问可审计性又希望日志不泄露真实 IP 的隐私敏感型用户