dsh-remote-gateway
在终端中运行以下命令:
dsh plugin install Jiachi5533/dsh-remote-gateway
将以下提示词粘贴到 DeepSeek Harness 对话框中:
在 DeepSeek Harness 终端执行 dsh plugin install Jiachi5533/dsh-remote-gateway,插件源码地址为 https://github.com/Jiachi5533/dsh-remote-gateway
插件介绍
DSH intentionally keeps its privileged browser capabilities on loopback, so a plain reverse proxy that lets a remote browser render the page will immediately run into broken settings, failed plugin-bundle loads, dropped WebSockets, and host-directory-selection errors. dsh-remote-gateway slots in between your authenticated reverse proxy and the internal DSH server as a narrow compatibility layer, passing through unrelated plugin assets byte-for-byte while patching only the exact connection probe so the remote UI stays fully functional.
The gateway proxies HTTP, SSE, and WebSocket traffic in parallel, rewrites the upstream Host and Origin to the loopback authority, and strips every edge-authentication and forwarded-client-identity header before a request reaches DSH. When a remote user needs to pick a workspace directory, the native OS file dialog is transparently replaced by DSH's in-app filesystem browser, removing a common source of privilege leakage. The gateway also starts and stops with the DSH plugin lifecycle, so an existing systemd, launchd, or other supervisor handles it automatically.
If you already run DSH locally under a process supervisor and want a small trusted team to reach it over an authenticated, TLS-terminating reverse proxy, this plugin is the lowest-friction bridge. The source-IP allowlist adds a second, independent gate on top of the proxy's own access control, making sure only the single gateway address you designate can ever speak to the loopback-bound DSH server.
截图预览
使用场景
- 通过认证反向代理在局域网内安全访问本地 DSH
- 为远程浏览器修复设置、插件、WebSocket 和目录选择异常
- 在不直接暴露 3080 端口的情况下提供受控远程访问
适合人员
- 需要让可信团队远程访问本地 DSH 的运维人员
- 已经使用 systemd 或 launchd 管理 DSH 的站长
- 需要为 DSH 增加源 IP 白名单和请求头清洗的管理者