Chuyển đến nội dung chính

dsh-web-auth-gateway

Đã xác minh

dsh-web-auth-gateway · v0.1.0 · BSD-3-Clause · Giao diện web

Authentication reverse-proxy gateway for DeepSeek Harness Web

Cài đặt

dsh plugin add dsh-web-auth-gateway

Xác nhận layer đã áp bằng dsh --profile default --dump-config — xem hướng dẫn cài plugin.

Mã nguồn

Tác giả

Readme

dsh-web-auth-gateway

A standalone authentication reverse-proxy gateway plugin for DeepSeek Harness Web.

The plugin serves a login page on a separate loopback port. After authentication, it proxies the complete DSH Web surface, including normal pages, plugin assets, API requests, and WebSocket upgrades.

Features

  • First-run administrator account creation
  • scrypt salted password hashing; plaintext passwords are never stored
  • HttpOnly and SameSite=Strict session cookie
  • Server-side in-memory sessions
  • HTTP, API, and WebSocket authentication gate
  • Native-style settings card under Settings > Plugins > Plugin configuration
  • Configurable gateway port and session lifetime
  • Editable administrator username and password
  • Gateway-only loopback classification for DSH Web's protected settings surface
  • Official @deepseek-ai/* NPM SDK only
  • No changes to DeepSeek Harness source code

Install

Requires Node.js 22 or newer and DeepSeek Harness 0.1.0-rc.6 or newer.

Published package

Install through the official DSH plugin command:

dsh plugin --profile web add dsh-web-auth-gateway

dsh plugin installs the package into the selected profile and automatically adds packages that declare a dsh.bundle layer to the profile composition. There is no need to edit package.json by hand.

Local checkout

For development or a private checkout, install the local package with the same official entry point:

dsh plugin --profile web add /root/codes/dsh-web-auth-gateway

Restart DSH Web:

dsh web --host 127.0.0.1 --port 3080

Then open:

http://127.0.0.1:3090

On first access, create the administrator account. Later visits require that account. The login page intentionally leaves the username blank.

Settings

Open Settings > Plugins > Plugin configuration > Login gateway.

Gateway settings

The settings card controls:

  • Enable/disable the gateway
  • Listen address and port
  • Session lifetime
  • Administrator account card
  • Separate username and password editing actions

Example configuration for LAN access:

enabled: true
host: 0.0.0.0
port: 55208
sessionTtlHours: 12

Settings are persisted through the official DSH Settings service in ~/.dsh/settings.yaml.

Changing only the username keeps existing sessions alive. Changing the password invalidates existing sessions and requires signing in again.

Login page

First-run administrator setup

The credential file is stored at:

~/.dsh/web-auth-gateway/credential.json

The file contains only the username, random salt, and scrypt password hash. Its mode is 0600; plaintext passwords are never written to disk.

Security boundary

The original DSH Web port must remain bound to 127.0.0.1 or another trusted interface. If the upstream port is exposed to untrusted clients, they can bypass the gateway.

For remote access, use a TLS reverse proxy or a secure tunnel in front of the gateway. Do not expose plaintext HTTP directly to an untrusted network. The gateway rewrites DSH's client connection metadata only on the authenticated gateway route, so DSH can keep its loopback-only settings capability while the original 3080 endpoint retains its normal behavior.

Sessions are stored in memory and are invalidated when DSH restarts.

Development

corepack enable
pnpm install
pnpm build
pnpm typecheck
pnpm test

Install the local checkout into the Web profile:

dsh plugin --profile web add link:$(pwd)

After changing source files, rebuild and restart the profile:

pnpm build
dsh web --host 127.0.0.1 --port 3080

License

BSD-3-Clause