534119219/chicheng-gate
DSH Web 插件:局域网/远程访问控制、frpc 内网穿透、面板密码门禁与手机端 UI 适配。
Project Overview项目介绍
Chicheng-gate is a native plugin built exclusively for the DeepSeek Harness (DSH) Web GUI, adding remote access management, frp-based intranet penetration, password authentication for external access, and mobile-friendly UI adjustments. You can install it directly via the DSH CLI by running the command dsh plugin --profile web add github:534119219/chicheng-gate, which automatically adds it to your profile's dependency list. All configuration options are available directly in the DSH Web GUI settings panel, so you do not need to edit any configuration files manually to use its core features. It lets you toggle between binding DSH to localhost only or all network interfaces, automatically restore all changes when you turn off remote access, automatically download and launch frpc to expose DSH to the public internet, requires password checks for all non-local access attempts and injects custom CSS to make the DSH interface usable on mobile devices.
This plugin is designed for developers who need to access their local DSH instance from an external device or over the public internet. The standard workflow after installation is straightforward: open the DSH Web GUI, navigate to Settings, select Chicheng Gate from the sidebar, confirm the required security warning on first run, set your panel password if you plan to expose DSH externally, configure your frp server details if you want public access, toggle on the features you need, and restart the DSH Web service to apply all configuration changes. Most feature toggles work in real time, but changes to core network binding and frp configuration require a restart to take full effect. Local access from 127.0.0.1 remains password-free even when you enable the password gate for external access, so you do not need to log in every time you use DSH from the host machine.
Chicheng-gate is released under the permissive MIT open source license, and it does not require any additional dependencies beyond a working DSH Web installation. It automatically downloads the frpc binary from GitHub Releases on first run, verifies the SHA256 checksum to ensure integrity, and falls back to a manual path if the download fails. You must read and accept the security warnings before using this plugin, because exposing DSH to a public network or untrusted LAN gives anyone who accesses it full control over your DSH instance, including access to your files, terminals, credentials and code execution. The plugin implements multiple security measures like scrypt salted password hashing, rate limiting for login attempts, 7-day session cookies, and a separate password gateway that only forwards authenticated requests to DSH, but you must still use a strong password and only expose DSH when you are on a trusted network.
赤橙网关(chicheng-gate)是专门为 DeepSeek Harness (DSH) Web GUI 开发的原生插件,提供远程访问控制、frpc 内网穿透、面板密码门禁和手机端 UI 适配功能,所有配置都能在 DSH 的设置面板中统一管理。核心功能包括一键切换 Web GUI 绑定地址,可开放给局域网设备访问,关闭后自动还原配置;自动下载拉起 frpc 将面板映射到公网;对非本机访问强制密码验证,并适配移动端显示界面。
适合需要在外网或非本机环境访问自己本地 DSH 实例的开发者使用。典型使用流程为:安装插件后打开 Web GUI 设置,侧栏选择赤橙网关,首次使用需要确认安全风险,然后设置面板密码(推荐),按需配置 frpc 内网穿透参数,最后开启远程访问或 frpc 开关,修改配置后重启 DSH Web 即可生效。所有开关都支持随时调整,关闭对应功能后会自动还原所有配置修改。
插件遵循 MIT 开源许可协议,使用前必须注意安全风险:开启远程访问会绑定到所有网卡,局域网内任何设备都可访问你的 DSH 实例;开启 frpc 内网穿透会将面板暴露到公网,强烈建议同时设置强面板密码。仅在信任的网络使用该插件,公网/不可信网络开启会暴露完整控制权给他人。
请帮我安装这个 DSH 插件。安装前先完成【兼容性检查 + 安全性检查】,检查通过再动手。
插件:chicheng-gate(534119219/chicheng-gate)
仓库:https://github.com/534119219/chicheng-gate
本站详情页:https://www.yhbd.top/plugins/534119219-chicheng-gate/
本站登记:类型 plugin · 归类 原生 DSH 插件 · 许可证 MIT · ⭐ 5 · 最近提交 2026-08-20 · 主语言 JavaScript
按下面顺序执行,每步先把结论告诉我,再进入下一步:
【1 兼容性检查】
① 我这边:DSH 版本、Node 版本、操作系统、当前 profile(web / desktop)。
② 读它的 README、package.json、插件 manifest,列出它要求的 DSH 版本 / Node 版本 / 操作系统 / 外部依赖 / 需要另外先装的运行时。
③ 逐条比对,结论只写「满足 / 不满足 / 未知」三种;不满足的给出可行替代方案。
④ 检查是否和我已装的插件冲突:命令名重复、skill / tool 重名、端口占用、重复注册的 MCP server。
【2 安全性检查】
① 仓库可信度:和上面「本站登记」是否一致;star / fork 数、创建时间、最近提交,是否归档或长期停更。
② 安装脚本:逐行看 package.json 的 preinstall / install / postinstall,以及 install.sh、setup.ps1 之类脚本。出现 curl|bash、下载后直接执行、混淆代码、访问与插件功能无关的域名,立刻停下来告诉我,不要继续装。
③ 依赖:列出新增依赖,标出无人维护、或与知名包拼写近似的可疑包(typosquatting)。
④ 权限与副作用:它会读写哪些目录、访问哪些域名、需要哪些 DSH 权限(filesystem / network / shell / clipboard 等),以及怎么卸载和回滚。
⑤ 如果它要求 sudo / 管理员权限,或权限明显超出功能所需,先停下来问我。
【3 安装】
上面两步没有「不满足」和「高危项」时才执行;用官方推荐方式安装,不要自行提权。
【4 汇报】
用表格输出:检查项 / 结论 / 依据 / 是否需要我决策。拿不准的一律写「未知」并说明要我怎么确认——不要猜,也不要替我决定。
Send this message to DSH in your current session: it verifies compatibility and security first (answering met / not met / unknown item by item) and only installs once everything checks out — it will stop and ask you if it finds a high-risk item. The box scrolls; the copy is the full prompt. CLI install commands may not be accurate across systems, so DSH is the safer route.把上面这条消息直接发给当前会话里的 DSH:它会先核对兼容性与安全性(逐条给「满足 / 不满足 / 未知」),确认没问题再安装,有高危项会停下来问你。框内可滚动,复制到的是完整提示词;安装命令不一定准确,发给 DSH 更稳。
- Only 5 stars - very few users, little community feedback星标只有 5,几乎没人在用,遇到问题缺少社区反馈
DSH walks through these 9 checksDSH 会逐条核对这 9 项
Compatibility兼容性
- DSH, Node, OS and profile requirementsDSH 版本 / Node 版本 / 操作系统 / profile 是否满足要求
- External dependencies and runtimes (Electron / Python / Docker, ...)外部依赖与运行时(Electron / Python / Docker 等)是否齐备
- Conflicts with installed plugins: command names, skill / tool names, ports, duplicate MCP registration与已装插件是否冲突:命令名、skill / tool 重名、端口占用、重复 MCP 注册
Security安全性
- Repo matches the facts registered here; archived or abandoned?仓库是否与页面登记一致,是否归档或长期停更
- Safety of preinstall / install / postinstall and install.sh / setup.ps1preinstall / install / postinstall 与 install.sh、setup.ps1 是否安全
- curl|bash, download-then-execute, obfuscation, unrelated domains → stop immediatelycurl|bash、下载即执行、混淆代码、无关域名 → 立刻停止
- Typosquatting or unmaintained packages among the new dependencies新增依赖里有没有 typosquatting 或无人维护的包
- Requested permissions vs. what the feature actually needs申请了哪些权限、是否超出功能所需(filesystem / network / shell / clipboard)
- Any sudo / admin requirement, plus uninstall and rollback是否要求 sudo / 管理员权限,以及卸载与回滚方式
Anything uncertain must be marked unknown with a note on how to confirm it. This site's signal screen is a static snapshot, not a security audit.拿不准的必须标「未知」并说明要我怎么确认。本站的信号筛查是静态快照,不能替代安全审计。
Or use CLI install (for developers)或使用命令行安装(适合开发者)
CLI Install命令行安装
dsh plugin --profile web add github:534119219/chicheng-gate
把 534119219/chicheng-gate 加入你的 DSH 配置(web profile)即可启用。
READMEREADME
chicheng-gate
DSH Web GUI 插件:远程访问控制 + frpc 内网穿透 + 面板密码门禁 + 手机端 UI 适配。
在设置面板里统一管理:
- 远程访问:一键切换 Web GUI 绑定 0.0.0.0 / 127.0.0.1,让局域网设备可访问;关闭时自动还原所有修改。
- frpc 内网穿透:自动下载并拉起 frpc,把面板映射到公网 frps 服务器,可随时开/停。
- 面板密码门禁:非本机访问必须先通过密码验证(scrypt 加盐哈希 + 会话 cookie + 登录限速)。
- 手机端 UI:注入移动端适配 CSS。
⚠️ 安全警告(务必先读)
开启「远程访问」会把 Web GUI 绑定到 0.0.0.0(所有网卡),局域网内任何设备都能访问并操作你的 Harness(会话、文件、终端、凭据、代码执行等)。
开启「frpc 内网穿透」会把面板暴露到公网。强烈建议同时设置「面板密码」——本插件的密码门禁会对所有非本机访问(包括走 frp 隧道的访问)要求先登录。
- 仅在你信任的网络使用。
- 公网 / 不可信网络开启,等同于把完整控制权暴露给他人,请务必设置强密码。
功能特性
- 远程访问开关(默认关):切换 0.0.0.0 与 127.0.0.1 绑定;关闭时还原全部修改。
- frpc 内网穿透(默认关,实时开关):启动时自动从 GitHub Releases 下载 frpc(带 SHA256 校验,失败回退手动路径),生成 frpc.toml 并拉起;取消勾选立即停止。配置项:服务器地址/端口、token 验证、本机端口、远程端口。
- 面板密码门禁:非 127.0.0.1 来源必须先通过密码验证;密码只存加盐哈希,带登录限速(5 次/分/IP)与 7 天会话。
- 独立密码网关:frpc 隧道不直连 DSH,而是先经过一个本地密码网关(127.0.0.1 的「本机端口」,默认 3081),验证通过后才转发到 DSH 主端口 3080——这样公网隧道也需要密码,而本机 127.0.0.1 免密访问不受影响。
- 手机端 UI 调整(默认开):注入移动端适配 CSS。
- 首次使用安全确认:阅读并确认风险后才解锁开关。
- crypto.randomUUID 补丁:修复局域网 HTTP 下 randomUUID 缺失。
截图
![]() 设置页 |
![]() 密码登录页 |
![]() 手机端 1 |
![]() 手机端 2 |
![]() 手机端 3 |
安装
GitHub 安装:
dsh plugin --profile web add github:534119219/chicheng-gate
安装后在 profile 的 package.json 里会得到:
"dependencies": {
"chicheng-gate": "github:534119219/chicheng-gate"
}
使用
- 打开 Web GUI → 设置 → 侧栏选「赤橙网关」。
- 首次进入弹出安全确认,勾选「我已阅读并了解上述安全风险」→ 点「同意」。
- 设置面板密码(推荐):在「面板密码」卡片输入至少 8 位密码并保存。
- 配置 frpc(如需公网访问):在「内网穿透 (frpc)」卡片填服务器地址、端口、token、本机端口(默认 3081,不可用 3080)、远程端口。
- 打开「远程访问」开关(局域网访问)和/或「启用 frpc」(公网访问)。
- 重启 dsh web(远程访问和 frpc 配置改动需重启生效;frpc 的启用/停用开关本身是实时的)。
- 访问:
- 局域网:http://<本机IP>:3080
- 公网(frpc 隧道):http://<frps公网IP>:<远程端口> —— 首次会弹登录页,输入面板密码。
工作原理
- 主机侧(lib/index.js):
- 启动早期读取设置,提供 remoteAccess 服务(决定 webserver.host 与 connection.trustedHosts),并给 web-runtime 注入同一 trust 列表(供 /api 与 dsh-better-sidebar 等 fence 使用)。
- 按开关应用/还原 3 处官方源码补丁(打补丁前自动备份 .chicheng-gate.bak,关闭时还原):远程访问(connection 特权方法白名单、设置持久化 host)、手机端两步设置、设置侧栏网关图标。
- 面板密码门禁:包住 HTTP server 的 request/upgrade,非本机访问要求会话 cookie;提供 /chicheng-gate/login、/chicheng-gate/logout、/chicheng-gate/password、/chicheng-gate/status、/chicheng-gate/restart 路由。
- frpc 管理:自动下载/启动/停止 frpc(存放于 $DSH_HOME/frpc/,PID 记在 frpc.pid),按设置实时开关。
- 独立密码网关:监听 127.0.0.1 的「本机端口」,反向代理(HTTP + WebSocket + SSE)到 DSH 主端口,复用同一套密码/会话。
- 客户端(lib/client.js):在设置侧栏注册「赤橙网关」分区,卡片式渲染远程访问 / 面板密码 / frpc / 手机端 UI,通过 settingsScope 读写设置。
Showing the opening section of the README — the full document lives in the repository以上为 README 开头摘要,完整文档在仓库内 · View the full README on GitHub →在 GitHub 查看完整 README →





shaobeichen/dsh-pocket
ningbainb/deepseek-harness-desktop
chokwinlee/deepseek-harness-desktop
SCSpotato/dsh-remote
dclichang2022/dsh-green-meter
omdsh-dev/dsh-notification
mrRisega/dsh-remote
Clarklevis1995/dsh-plugin-mobile-gateway