Asaiuta/dsh-custom-header

Project Overview项目介绍

dsh-custom-header is a Cordis plugin built specifically for DeepSeek Harness (DSH), operating at the fetch transport layer — one layer below the LLM SDK — to rewrite outbound HTTP headers, URL paths, and Anthropic Messages request bodies sent to upstream providers. It ships a set of fixed identity profiles (codex_desktop, codex_official, codex_tui, codex_claude_plugin, pi_agent, claude_code_messages, opencode_zen) whose User-Agent and Originator values mirror real Codex / Claude Code / opencode clients, plus an auto mode that picks Anthropic or Codex identities based on path matching against an explicit autoHosts allowlist. The README describes the install path as dsh plugin --profile web add file:$(pwd) (or the resolved package name) and full configuration through cordis.yml, with a Settings → Plugins → Custom Header tab exposing profile selection, the host allowlist, Claude system-block mode and version fields.

Typical workflow: a host or gateway operator decides whether to pin a fixed profile globally or leave auto with an empty allowlist (the safe default that touches nothing), then populates autoHosts with the upstream endpoints they want rewritten; on each request a single middleware pipeline (Symbol.for("dsh-custom-header.fetch.pipeline.v1")) runs header-inject (priority 7), header-strip (6), body-patch (8) and url-rewrite (5), with conversation scoping carried via AsyncLocalStorage seeded from GenerateOptions.sessionId. A llm/stream observer flags 403 / Cloudflare HTML responses in the log, and a programmatic API (ctx.dshCustomHeader.setProfile, ctx.dshCustomHeader.status()) is exposed for diagnostics. It is aimed at administrators of DSH gateways they control or are authorized to use, who need to send Codex / Claude Code / opencode-shaped client identity to specific upstreams, strip Stainless fingerprints, or append ?beta=true for Anthropic-compatible servers.

Dependencies are minimal: a Node runtime and a DSH host with the Cordis plugin slot; the fetch pipeline is vendored from @aizigao/pi-fetch-pipeline (MIT) and the plugin itself is MIT-licensed. Documented limits: Node undici injects accept-language / sec-fetch-mode below fetch and the plugin cannot remove them; opencode's x-opencode-* headers are only replicated for opencode providers, other paths fall back to x-session-affinity / X-Session-Id; fixed profiles inject globally regardless of autoHosts, so use auto when strict isolation is required; Cloudflare TLS/Bot edge blocks cannot be bypassed by header rewriting alone and need a different API entry, an allowlist, or a local forward proxy. First-run guidance: start with profile: "auto" and an empty autoHosts to verify zero interference, then check dsh-custom-header loaded: ... lines in the server log and run ctx.dshCustomHeader.status() for a diagnostics snapshot.

dsh-custom-header 是面向 DeepSeek Harness(DSH)的 Cordis 原生插件,工作在 fetch 传输层,对外发往 LLM 供应商的 HTTP 请求做头部与请求体的改写。它提供 codex_desktop、codex_official、codex_tui、codex_claude_plugin、pi_agent、claude_code_messages、opencode_zen、auto、off 等预设身份集,模仿 Codex、Claude Code、opencode 等真实客户端的 User-Agent 与 Originator 头,并按 autoHosts 白名单限定作用范围。安装方式为 dsh plugin --profile web add file:$(pwd) 或解析后的包名,加载后通过 cordis.yml 配置 profile、autoHosts 与 urlRewrites 等字段。

典型工作流是宿主管理员在 cordis.yml 中选定一个固定 profile,或保留 auto 并填写 autoHosts 让插件按路径自动选用 Anthropic / Codex 身份集,再在设置页的 Custom Header 选项卡中切换 profile、调试 claudeSystemMode 或调整版本号;请求经中间件管道(header-inject / header-strip / body-patch / url-rewrite / session-context)按优先级串行处理,sessionId 通过 AsyncLocalStorage 在每个对话内隔离。它主要面向自管或已获授权的 DSH 网关运维者,用于在不动服务端的前提下让出站请求携带特定客户端身份、剥离 X-Stainless-* 指纹、并按需追加 ?beta=true 等查询参数。

依赖方面仅要求 Node 环境与 DSH 的 Cordis 插件插槽,fetch 管线来自上游仓库 @aizigao/pi-fetch-pipeline(MIT),本插件同样以 MIT 发布。已知局限:Node undici 在 fetch 之下注入的 accept-language / sec-fetch-mode 不可移除;opencode 的 x-opencode-* 头仅对 opencode 提供方链路复制,其他链路会回落到 x-session-affinity;固定 profile 不受 autoHosts 约束,若需严格隔离请改用 auto;Cloudflare TLS/Bot 边缘拦截不能靠改头解决,需要换 API 入口、加白名单或本地正向代理。首次运行请先以 profile: "auto" 加空 autoHosts 确认零侵入,再用 ctx.dshCustomHeader.status() 与服务器日志中的 dsh-custom-header loaded: ... 诊断条目核对命中情况。

Pre-install check安装前体检Compatibility · Security兼容性 · 安全性 1 warning1 项注意
  • Only 2 stars - very few users, little community feedback星标只有 2,几乎没人在用,遇到问题缺少社区反馈
DSH walks through these 9 checksDSH 会逐条核对这 9 项

Compatibility兼容性

  • DSH, Node, OS and profile requirementsDSH 版本 / Node 版本 / 操作系统 / profile 是否满足要求
  • External dependencies and runtimes (Electron / Python / Docker, ...)外部依赖与运行时(Electron / Python / Docker 等)是否齐备
  • Conflicts with installed plugins: command names, skill / tool names, ports, duplicate MCP registration与已装插件是否冲突:命令名、skill / tool 重名、端口占用、重复 MCP 注册

Security安全性

  • Repo matches the facts registered here; archived or abandoned?仓库是否与页面登记一致,是否归档或长期停更
  • Safety of preinstall / install / postinstall and install.sh / setup.ps1preinstall / install / postinstall 与 install.sh、setup.ps1 是否安全
  • curl|bash, download-then-execute, obfuscation, unrelated domains → stop immediatelycurl|bash、下载即执行、混淆代码、无关域名 → 立刻停止
  • Typosquatting or unmaintained packages among the new dependencies新增依赖里有没有 typosquatting 或无人维护的包
  • Requested permissions vs. what the feature actually needs申请了哪些权限、是否超出功能所需(filesystem / network / shell / clipboard)
  • Any sudo / admin requirement, plus uninstall and rollback是否要求 sudo / 管理员权限,以及卸载与回滚方式

Anything uncertain must be marked unknown with a note on how to confirm it. This site's signal screen is a static snapshot, not a security audit.拿不准的必须标「未知」并说明要我怎么确认。本站的信号筛查是静态快照,不能替代安全审计。

Or use CLI install (for developers)或使用命令行安装(适合开发者)

CLI Install命令行安装

dsh plugin --profile web add github:Asaiuta/dsh-custom-header

把 Asaiuta/dsh-custom-header 加入你的 DSH 配置(web profile)即可启用。

READMEREADME

dsh-custom-header

Outbound LLM request header modification for DeepSeek Harness (DSH).

Operates at the fetch transport layer — one layer below the LLM SDK — and modifies the HTTP headers of outgoing provider requests:

  • injects client-identity headers (User-Agent, Originator, X-Claude-Code-Session-Id, x-opencode-*, …) from a set of presets that mirror real Codex / Claude Code / opencode clients
  • strips SDK runtime fingerprint headers (X-Stainless-*)
  • rewrites request URLs (path matching + appendQuery)
  • patches Anthropic Messages request bodies (identity / billing system block + metadata.user_id)

All of it is scoped by an explicit host allowlist (autoHosts) — nothing outside the allowlist is ever touched; the default auto profile with an empty allowlist sends every request through untouched.

For servers you administer or are authorized to use. Cloudflare TLS/Bot edge blocks need a different API entry, an admin allowlist, or a local forward proxy — see the troubleshooting section in the Chinese README.

How it works

DSH has no per-request header hook, so every modification lands at the fetch transport layer, sharing one middleware pipeline (Symbol.for("dsh-custom-header.fetch.pipeline.v1")):

mechanism middleware safety gate
header injection header-inject (priority 7) auto needs host match; fixed profiles always inject
fingerprint stripping header-strip (priority 6) autoHosts hosts only
Anthropic body patch body-patch (priority 8) Anthropic Messages paths only
URL rewrite url-rewrite (priority 5) autoHosts hosts only
session id scoping per-conversation: GenerateOptions.sessionId → AsyncLocalStorage → fetch middlewares (session-context.ts) —
403 hints llm/stream waterfall observer —

Safe default: profile: "auto" with empty autoHosts does nothing at all.

Profiles

Each fixed profile is a complete client-identity header set:

Profile Headers sent
codex_desktop codex_app/1.2026.0628 (Windows NT 10.0; Win64; x64) + Originator: codex_app
codex_official codex_cli_rs/0.147.0 (Windows 10.0.19045; x86_64) WindowsTerminal + Originator: codex_cli_rs
codex_tui codex-tui/0.147.0 (…; x86_64) WindowsTerminal + Originator: codex-tui
codex_claude_plugin Claude Code/0.5.0 (Macos 15.5; arm64) iTerm2.app + Originator: Claude Code
pi_agent pi-coding-agent/1.0 + Originator: pi (needs the server to accept this identity too)
claude_code_messages claude-cli/2.1.220 (external, sdk-cli) + X-Claude-Code-Session-Id + full anthropic-beta + body (metadata.user_id JSON / system block)
opencode_zen opencode/1.18.18 ai-sdk/... UA + x-opencode-client/project/session/request, strips X-Stainless-* fingerprints
auto autoHosts match: Anthropic Messages paths → Claude set; else → autoCodexProfile
off nothing

Showing the opening section of the README — the full document lives in the repository以上为 README 开头摘要,完整文档在仓库内 · View the full README on GitHub →在 GitHub 查看完整 README →

← 上一个 Prev dsh-pseudo-vision 下一个 Next dsh-tool-lsp →