dsh-secure-context-fix
在终端中运行以下命令:
dsh plugin install Li-Mingshuang/dsh-secure-context-fix
将以下提示词粘贴到 DeepSeek Harness 对话框中:
在 DeepSeek Harness 终端中执行安装命令,插件源码地址为 https://github.com/Li-Mingshuang/dsh-secure-context-fix ,安装完成后重启 profile 即可生效。
插件介绍
The DeepSeek Harness Web GUI uses crypto.randomUUID for RPC IDs, session keys, and image draft identifiers. Browsers only expose that API in secure contexts (HTTPS or localhost), so opening the GUI from a phone or another device over plain HTTP on your LAN makes every RPC crash: the workspace list never loads, the directory picker fails, and new sessions cannot be created — while the same URL on 127.0.0.1 works perfectly.
This plugin registers a webServer.tapIndex transform that injects a small inline script into index.html before any dsh bundle code runs. The script installs a crypto.randomUUID implementation backed by crypto.getRandomValues(), which browsers do expose on insecure origins. No official source changes, no polyfill library, no build step required. Install the plugin, restart your profile, and the GUI works from any LAN device.
It suits anyone who runs dsh from a phone or tablet over a home or office LAN without HTTPS. Binding the GUI to 0.0.0.0 exposes agent-level control to anyone who can reach the port, so use it only on a trusted network and restrict the firewall rule to your LAN subnet. This is a stop-gap for upstream issue #4209 — if you can patch the three randomUUID call sites directly, prefer that approach.
使用场景
- 从手机通过家庭 WiFi 以纯 HTTP 访问 dsh Web GUI 时工作区列表和目录选择器全部报错
- 在办公室局域网用平板打开 dsh 界面,localhost 正常但远程设备所有 RPC 崩溃
- 不想配 HTTPS 也不愿改 dsh 源码,需要一种无感修复方式让 Web GUI 在 LAN 上可用
适合人员
- 从手机或平板等移动设备通过局域网访问 dsh Web GUI 的用户
- 在家庭或办公网络中运行 dsh 且未部署 HTTPS 的开发者
- 无法直接修改 dsh 上游源码、需要纯插件方式修复的普通用户