Asaiuta/dsh-custom-header
Project Overview项目介绍
dsh-custom-header is a Cordis plugin built specifically for DeepSeek Harness (DSH), operating at the fetch transport layer — one layer below the LLM SDK — to rewrite outbound HTTP headers, URL paths, and Anthropic Messages request bodies sent to upstream providers. It ships a set of fixed identity profiles (codex_desktop, codex_official, codex_tui, codex_claude_plugin, pi_agent, claude_code_messages, opencode_zen) whose User-Agent and Originator values mirror real Codex / Claude Code / opencode clients, plus an auto mode that picks Anthropic or Codex identities based on path matching against an explicit autoHosts allowlist. The README describes the install path as dsh plugin --profile web add file:$(pwd) (or the resolved package name) and full configuration through cordis.yml, with a Settings → Plugins → Custom Header tab exposing profile selection, the host allowlist, Claude system-block mode and version fields.
Typical workflow: a host or gateway operator decides whether to pin a fixed profile globally or leave auto with an empty allowlist (the safe default that touches nothing), then populates autoHosts with the upstream endpoints they want rewritten; on each request a single middleware pipeline (Symbol.for("dsh-custom-header.fetch.pipeline.v1")) runs header-inject (priority 7), header-strip (6), body-patch (8) and url-rewrite (5), with conversation scoping carried via AsyncLocalStorage seeded from GenerateOptions.sessionId. A llm/stream observer flags 403 / Cloudflare HTML responses in the log, and a programmatic API (ctx.dshCustomHeader.setProfile, ctx.dshCustomHeader.status()) is exposed for diagnostics. It is aimed at administrators of DSH gateways they control or are authorized to use, who need to send Codex / Claude Code / opencode-shaped client identity to specific upstreams, strip Stainless fingerprints, or append ?beta=true for Anthropic-compatible servers.
Dependencies are minimal: a Node runtime and a DSH host with the Cordis plugin slot; the fetch pipeline is vendored from @aizigao/pi-fetch-pipeline (MIT) and the plugin itself is MIT-licensed. Documented limits: Node undici injects accept-language / sec-fetch-mode below fetch and the plugin cannot remove them; opencode's x-opencode-* headers are only replicated for opencode providers, other paths fall back to x-session-affinity / X-Session-Id; fixed profiles inject globally regardless of autoHosts, so use auto when strict isolation is required; Cloudflare TLS/Bot edge blocks cannot be bypassed by header rewriting alone and need a different API entry, an allowlist, or a local forward proxy. First-run guidance: start with profile: "auto" and an empty autoHosts to verify zero interference, then check dsh-custom-header loaded: ... lines in the server log and run ctx.dshCustomHeader.status() for a diagnostics snapshot.
dsh-custom-header 是面向 DeepSeek Harness(DSH)的 Cordis 原生插件,工作在 fetch 传输层,对外发往 LLM 供应商的 HTTP 请求做头部与请求体的改写。它提供 codex_desktop、codex_official、codex_tui、codex_claude_plugin、pi_agent、claude_code_messages、opencode_zen、auto、off 等预设身份集,模仿 Codex、Claude Code、opencode 等真实客户端的 User-Agent 与 Originator 头,并按 autoHosts 白名单限定作用范围。安装方式为 dsh plugin --profile web add file:$(pwd) 或解析后的包名,加载后通过 cordis.yml 配置 profile、autoHosts 与 urlRewrites 等字段。
典型工作流是宿主管理员在 cordis.yml 中选定一个固定 profile,或保留 auto 并填写 autoHosts 让插件按路径自动选用 Anthropic / Codex 身份集,再在设置页的 Custom Header 选项卡中切换 profile、调试 claudeSystemMode 或调整版本号;请求经中间件管道(header-inject / header-strip / body-patch / url-rewrite / session-context)按优先级串行处理,sessionId 通过 AsyncLocalStorage 在每个对话内隔离。它主要面向自管或已获授权的 DSH 网关运维者,用于在不动服务端的前提下让出站请求携带特定客户端身份、剥离 X-Stainless-* 指纹、并按需追加 ?beta=true 等查询参数。
依赖方面仅要求 Node 环境与 DSH 的 Cordis 插件插槽,fetch 管线来自上游仓库 @aizigao/pi-fetch-pipeline(MIT),本插件同样以 MIT 发布。已知局限:Node undici 在 fetch 之下注入的 accept-language / sec-fetch-mode 不可移除;opencode 的 x-opencode-* 头仅对 opencode 提供方链路复制,其他链路会回落到 x-session-affinity;固定 profile 不受 autoHosts 约束,若需严格隔离请改用 auto;Cloudflare TLS/Bot 边缘拦截不能靠改头解决,需要换 API 入口、加白名单或本地正向代理。首次运行请先以 profile: "auto" 加空 autoHosts 确认零侵入,再用 ctx.dshCustomHeader.status() 与服务器日志中的 dsh-custom-header loaded: ... 诊断条目核对命中情况。
请帮我安装这个 DSH 插件。安装前先完成【兼容性检查 + 安全性检查】,检查通过再动手。
插件:dsh-custom-header(Asaiuta/dsh-custom-header)
仓库:https://github.com/Asaiuta/dsh-custom-header
本站详情页:https://www.yhbd.top/plugins/asaiuta-dsh-custom-header/
本站登记:类型 plugin · 归类 原生 DSH 插件 · 许可证 MIT · ⭐ 2 · 最近提交 2026-08-15 · 主语言 TypeScript
按下面顺序执行,每步先把结论告诉我,再进入下一步:
【1 兼容性检查】
① 我这边:DSH 版本、Node 版本、操作系统、当前 profile(web / desktop)。
② 读它的 README、package.json、插件 manifest,列出它要求的 DSH 版本 / Node 版本 / 操作系统 / 外部依赖 / 需要另外先装的运行时。
③ 逐条比对,结论只写「满足 / 不满足 / 未知」三种;不满足的给出可行替代方案。
④ 检查是否和我已装的插件冲突:命令名重复、skill / tool 重名、端口占用、重复注册的 MCP server。
【2 安全性检查】
① 仓库可信度:和上面「本站登记」是否一致;star / fork 数、创建时间、最近提交,是否归档或长期停更。
② 安装脚本:逐行看 package.json 的 preinstall / install / postinstall,以及 install.sh、setup.ps1 之类脚本。出现 curl|bash、下载后直接执行、混淆代码、访问与插件功能无关的域名,立刻停下来告诉我,不要继续装。
③ 依赖:列出新增依赖,标出无人维护、或与知名包拼写近似的可疑包(typosquatting)。
④ 权限与副作用:它会读写哪些目录、访问哪些域名、需要哪些 DSH 权限(filesystem / network / shell / clipboard 等),以及怎么卸载和回滚。
⑤ 如果它要求 sudo / 管理员权限,或权限明显超出功能所需,先停下来问我。
【3 安装】
上面两步没有「不满足」和「高危项」时才执行;用官方推荐方式安装,不要自行提权。
【4 汇报】
用表格输出:检查项 / 结论 / 依据 / 是否需要我决策。拿不准的一律写「未知」并说明要我怎么确认——不要猜,也不要替我决定。
Send this message to DSH in your current session: it verifies compatibility and security first (answering met / not met / unknown item by item) and only installs once everything checks out — it will stop and ask you if it finds a high-risk item. The box scrolls; the copy is the full prompt. CLI install commands may not be accurate across systems, so DSH is the safer route.把上面这条消息直接发给当前会话里的 DSH:它会先核对兼容性与安全性(逐条给「满足 / 不满足 / 未知」),确认没问题再安装,有高危项会停下来问你。框内可滚动,复制到的是完整提示词;安装命令不一定准确,发给 DSH 更稳。
- Only 2 stars - very few users, little community feedback星标只有 2,几乎没人在用,遇到问题缺少社区反馈
DSH walks through these 9 checksDSH 会逐条核对这 9 项
Compatibility兼容性
- DSH, Node, OS and profile requirementsDSH 版本 / Node 版本 / 操作系统 / profile 是否满足要求
- External dependencies and runtimes (Electron / Python / Docker, ...)外部依赖与运行时(Electron / Python / Docker 等)是否齐备
- Conflicts with installed plugins: command names, skill / tool names, ports, duplicate MCP registration与已装插件是否冲突:命令名、skill / tool 重名、端口占用、重复 MCP 注册
Security安全性
- Repo matches the facts registered here; archived or abandoned?仓库是否与页面登记一致,是否归档或长期停更
- Safety of preinstall / install / postinstall and install.sh / setup.ps1preinstall / install / postinstall 与 install.sh、setup.ps1 是否安全
- curl|bash, download-then-execute, obfuscation, unrelated domains → stop immediatelycurl|bash、下载即执行、混淆代码、无关域名 → 立刻停止
- Typosquatting or unmaintained packages among the new dependencies新增依赖里有没有 typosquatting 或无人维护的包
- Requested permissions vs. what the feature actually needs申请了哪些权限、是否超出功能所需(filesystem / network / shell / clipboard)
- Any sudo / admin requirement, plus uninstall and rollback是否要求 sudo / 管理员权限,以及卸载与回滚方式
Anything uncertain must be marked unknown with a note on how to confirm it. This site's signal screen is a static snapshot, not a security audit.拿不准的必须标「未知」并说明要我怎么确认。本站的信号筛查是静态快照,不能替代安全审计。
Or use CLI install (for developers)或使用命令行安装(适合开发者)
CLI Install命令行安装
dsh plugin --profile web add github:Asaiuta/dsh-custom-header
把 Asaiuta/dsh-custom-header 加入你的 DSH 配置(web profile)即可启用。
READMEREADME
dsh-custom-header
Outbound LLM request header modification for DeepSeek Harness (DSH).
Operates at the fetch transport layer — one layer below the LLM SDK — and modifies the HTTP headers of outgoing provider requests:
- injects client-identity headers (
User-Agent,Originator,X-Claude-Code-Session-Id,x-opencode-*, …) from a set of presets that mirror real Codex / Claude Code / opencode clients - strips SDK runtime fingerprint headers (
X-Stainless-*) - rewrites request URLs (path matching +
appendQuery) - patches Anthropic Messages request bodies (identity / billing system
block +
metadata.user_id)
All of it is scoped by an explicit host allowlist (autoHosts) — nothing
outside the allowlist is ever touched; the default auto profile with an
empty allowlist sends every request through untouched.
For servers you administer or are authorized to use. Cloudflare TLS/Bot edge blocks need a different API entry, an admin allowlist, or a local forward proxy — see the troubleshooting section in the Chinese README.
How it works
DSH has no per-request header hook, so every modification lands at the
fetch transport layer, sharing one middleware pipeline
(Symbol.for("dsh-custom-header.fetch.pipeline.v1")):
| mechanism | middleware | safety gate |
|---|---|---|
| header injection | header-inject (priority 7) |
auto needs host match; fixed profiles always inject |
| fingerprint stripping | header-strip (priority 6) |
autoHosts hosts only |
| Anthropic body patch | body-patch (priority 8) |
Anthropic Messages paths only |
| URL rewrite | url-rewrite (priority 5) |
autoHosts hosts only |
| session id scoping | per-conversation: GenerateOptions.sessionId → AsyncLocalStorage → fetch middlewares (session-context.ts) |
— |
| 403 hints | llm/stream waterfall observer |
— |
Safe default: profile: "auto" with empty autoHosts does nothing at all.
Profiles
Each fixed profile is a complete client-identity header set:
| Profile | Headers sent |
|---|---|
codex_desktop |
codex_app/1.2026.0628 (Windows NT 10.0; Win64; x64) + Originator: codex_app |
codex_official |
codex_cli_rs/0.147.0 (Windows 10.0.19045; x86_64) WindowsTerminal + Originator: codex_cli_rs |
codex_tui |
codex-tui/0.147.0 (…; x86_64) WindowsTerminal + Originator: codex-tui |
codex_claude_plugin |
Claude Code/0.5.0 (Macos 15.5; arm64) iTerm2.app + Originator: Claude Code |
pi_agent |
pi-coding-agent/1.0 + Originator: pi (needs the server to accept this identity too) |
claude_code_messages |
claude-cli/2.1.220 (external, sdk-cli) + X-Claude-Code-Session-Id + full anthropic-beta + body (metadata.user_id JSON / system block) |
opencode_zen |
opencode/1.18.18 ai-sdk/... UA + x-opencode-client/project/session/request, strips X-Stainless-* fingerprints |
auto |
autoHosts match: Anthropic Messages paths → Claude set; else → autoCodexProfile |
off |
nothing |
Showing the opening section of the README — the full document lives in the repository以上为 README 开头摘要,完整文档在仓库内 · View the full README on GitHub →在 GitHub 查看完整 README →
extracurricular-ai/dsh-filesnap
SenmuuuuW/dsh-whale-report
SnowCrescenter-tech/dsh-milestone
PerryLink/dsh-checkpoint-rewind
XieZongChen/dsh-md-notes
TencentCloud/tencentcloud-agentobs-sdk-dsh