dsh-web-auth-gateway
已验证dsh-web-auth-gateway · v0.1.0 · BSD-3-Clause · Web 界面
Authentication reverse-proxy gateway for DeepSeek Harness Web
安装
dsh plugin add dsh-web-auth-gateway 用 dsh --profile default --dump-config 确认 layer 已生效 —— 参见安装指南。
源码
作者
说明文档
dsh-web-auth-gateway
A standalone authentication reverse-proxy gateway plugin for DeepSeek Harness Web.
The plugin serves a login page on a separate loopback port. After authentication, it proxies the complete DSH Web surface, including normal pages, plugin assets, API requests, and WebSocket upgrades.
Features
- First-run administrator account creation
- scrypt salted password hashing; plaintext passwords are never stored
- HttpOnly and SameSite=Strict session cookie
- Server-side in-memory sessions
- HTTP, API, and WebSocket authentication gate
- Native-style settings card under
Settings > Plugins > Plugin configuration - Configurable gateway port and session lifetime
- Editable administrator username and password
- Gateway-only loopback classification for DSH Web's protected settings surface
- Official
@deepseek-ai/*NPM SDK only - No changes to DeepSeek Harness source code
Install
Requires Node.js 22 or newer and DeepSeek Harness 0.1.0-rc.6 or newer.
Published package
Install through the official DSH plugin command:
dsh plugin --profile web add dsh-web-auth-gateway
dsh plugin installs the package into the selected profile and automatically
adds packages that declare a dsh.bundle layer to the profile composition.
There is no need to edit package.json by hand.
Local checkout
For development or a private checkout, install the local package with the same official entry point:
dsh plugin --profile web add /root/codes/dsh-web-auth-gateway
Restart DSH Web:
dsh web --host 127.0.0.1 --port 3080
Then open:
http://127.0.0.1:3090
On first access, create the administrator account. Later visits require that account. The login page intentionally leaves the username blank.
Settings
Open Settings > Plugins > Plugin configuration > Login gateway.

The settings card controls:
- Enable/disable the gateway
- Listen address and port
- Session lifetime
- Administrator account card
- Separate username and password editing actions
Example configuration for LAN access:
enabled: true
host: 0.0.0.0
port: 55208
sessionTtlHours: 12
Settings are persisted through the official DSH Settings service in ~/.dsh/settings.yaml.
Changing only the username keeps existing sessions alive. Changing the password invalidates existing sessions and requires signing in again.
Login page

The credential file is stored at:
~/.dsh/web-auth-gateway/credential.json
The file contains only the username, random salt, and scrypt password hash. Its
mode is 0600; plaintext passwords are never written to disk.
Security boundary
The original DSH Web port must remain bound to 127.0.0.1 or another trusted
interface. If the upstream port is exposed to untrusted clients, they can
bypass the gateway.
For remote access, use a TLS reverse proxy or a secure tunnel in front of the
gateway. Do not expose plaintext HTTP directly to an untrusted network. The
gateway rewrites DSH's client connection metadata only on the authenticated
gateway route, so DSH can keep its loopback-only settings capability while the
original 3080 endpoint retains its normal behavior.
Sessions are stored in memory and are invalidated when DSH restarts.
Development
corepack enable
pnpm install
pnpm build
pnpm typecheck
pnpm test
Install the local checkout into the Web profile:
dsh plugin --profile web add link:$(pwd)
After changing source files, rebuild and restart the profile:
pnpm build
dsh web --host 127.0.0.1 --port 3080
License
BSD-3-Clause