Bernardxu123/dsh-mobile-gate 预览 preview

Bernardxu123/dsh-mobile-gate

LAN mobile gateway for DeepSeek Harness (DSH): 即插即用网关,支持首次访问审批、设备级令牌、速率限制及移动端布局注入。

Project Overview项目介绍

This is a DSH-native plugin that functions as a local area network gateway to let mobile devices access your computer’s DSH Web UI securely. It runs as a separate subprocess from the main DSH service, so it does not modify any core DSH configurations or alter the existing trust boundary that DSH maintains by only listening on 127.0.0.1. It includes multiple security features to prevent unauthorized access, including first-connection device approval, one-time device-bound tokens, and per-IP rate limiting, and it automatically injects a mobile-optimized layout into the DSH UI when accessed from a phone.

There are three supported installation methods for this plugin. The standard method is using the official DSH CLI command dsh plugin add ./dsh-mobile-gate which automatically activates the plugin thanks to the included DSH bundle manifest. You can also manually clone the repository and statically mount it by adding an entry to your DSH profile’s cordis.patch.yml file, or load it as a dynamic plugin without restarting your existing DSH session. After installation, the gateway listens on port 3088 by default, and you can access the admin dashboard from your local computer at http://127.0.0.1:3088/lan-gate/admin to manage connected devices.

The core gateway server is a single 30KB zero-dependency Node.js file, so no extra npm dependencies are required to run it beyond what DSH already provides. It is released under the permissive MIT open source license, so you can modify and redistribute it freely per the license terms. By default, it enforces a rate limit of 120 requests per minute per IP, and stores approved device records in a local JSON file at ~/.dsh/lan-gate-state.json that persists across DSH restarts. It is only intended for use on trusted local networks, as it does not add end-to-end encryption for traffic across untrusted public networks.

dsh-mobile-gate 是 DeepSeek Harness(DSH)的原生插件,作用是提供局域网手机访问本机 DSH Web UI 的安全网关。它让同一局域网内的手机、平板等移动设备能够访问本地运行的 DSH 服务,同时自动注入移动端适配排版,还自带访问审批、设备绑定、限流等安全控制能力,以独立子进程运行,不侵入修改 DSH 主服务。

用户可通过三种方式安装本插件:官方 dsh plugin add 命令一键安装、静态挂载到 DSH 配置补丁,或是作为动态插件即时加载无需重启 DSH。安装后网关默认监听 3088 端口,用户只需让手机连接同一 Wi-Fi,访问对应地址后在电脑端管理页批准设备即可使用,适合需要临时在外用手机访问本机 DSH 又保障安全的用户。

本插件采用 MIT 开源许可,核心网关服务是单文件零依赖的 Node.js 服务,仅需 DSH 本身运行环境即可启动。默认对每个 IP 每分钟限流 120 次请求,仅限可信局域网使用,不支持跨公网未加密访问。批准设备记录持久化存储在本地,重启 DSH 后已批准设备仍可正常访问。

Pre-install check安装前体检Compatibility · Security兼容性 · 安全性 1 warning1 项注意
  • Only 6 stars - very few users, little community feedback星标只有 6,几乎没人在用,遇到问题缺少社区反馈
DSH walks through these 9 checksDSH 会逐条核对这 9 项

Compatibility兼容性

  • DSH, Node, OS and profile requirementsDSH 版本 / Node 版本 / 操作系统 / profile 是否满足要求
  • External dependencies and runtimes (Electron / Python / Docker, ...)外部依赖与运行时(Electron / Python / Docker 等)是否齐备
  • Conflicts with installed plugins: command names, skill / tool names, ports, duplicate MCP registration与已装插件是否冲突:命令名、skill / tool 重名、端口占用、重复 MCP 注册

Security安全性

  • Repo matches the facts registered here; archived or abandoned?仓库是否与页面登记一致,是否归档或长期停更
  • Safety of preinstall / install / postinstall and install.sh / setup.ps1preinstall / install / postinstall 与 install.sh、setup.ps1 是否安全
  • curl|bash, download-then-execute, obfuscation, unrelated domains → stop immediatelycurl|bash、下载即执行、混淆代码、无关域名 → 立刻停止
  • Typosquatting or unmaintained packages among the new dependencies新增依赖里有没有 typosquatting 或无人维护的包
  • Requested permissions vs. what the feature actually needs申请了哪些权限、是否超出功能所需(filesystem / network / shell / clipboard)
  • Any sudo / admin requirement, plus uninstall and rollback是否要求 sudo / 管理员权限,以及卸载与回滚方式

Anything uncertain must be marked unknown with a note on how to confirm it. This site's signal screen is a static snapshot, not a security audit.拿不准的必须标「未知」并说明要我怎么确认。本站的信号筛查是静态快照,不能替代安全审计。

Or use CLI install (for developers)或使用命令行安装(适合开发者)

CLI Install命令行安装

dsh plugin --profile web add github:Bernardxu123/dsh-mobile-gate

把 Bernardxu123/dsh-mobile-gate 加入你的 DSH 配置(web profile)即可启用。

READMEREADME

dsh-mobile-gate · DSH 局域网手机访问网关

让局域网内的手机、平板等设备安全访问本机 DeepSeek Harness (DSH) Web UI,并自动注入手机端紧凑排版。

English: README.en.md · LLM 索引: llms.txt · Agent 指南: AGENTS.md

dsh-plugin DeepSeek Harness license install

关键词 / Keywords: dsh-plugin · deepseek-harness-plugin · 局域网 · LAN · 手机访问 · mobile · 反向代理 · reverse-proxy · 远程访问 · remote-access · 审批 · approval · 网关 · gateway


📑 目录


✨ 特性

特性 说明
📱 手机端适配 代理 HTML 时自动注入 data-lan-device 标记 + 紧凑排版 CSS + crypto.randomUUID polyfill(HTTP 非安全上下文必需),输入区权限/模型选择器压缩为小胶囊按钮,不再重叠
🔒 首次访问审批 手机第一次访问显示「等待本机批准」,需在电脑上手动允许,杜绝未授权设备访问
🎟️ 设备令牌 + Cookie 绑定 批准后生成一次性令牌,一次批准只绑定一个浏览器,令牌无法被其他设备复用
🛡️ 每 IP 限流 默认每分钟 120 次请求,超限返回 429,防止滥用
🏠 本机免审批 回环地址与本机 LAN IP 直接放行,电脑端体验不变
🚀 零侵入主服务 独立子进程网关,不动 DSH 主服务——webserver 仍只监听 127.0.0.1,/api 信任栅栏不受影响;网关挂掉也不影响 DSH
🧹 即插即用 / 可卸载 dsh plugin add 安装、cordis.patch.yml 挂载、或动态插件,三种方式;移除即终止

🏗️ 工作原理

手机 http://192.168.31.108:3088
  └─ 网关(独立 Node 进程,0.0.0.0:3088)
       ├─ 未批准 → 「等待本机批准」页面(含设备 IP,自动轮询)
       ├─ 已批准 + Cookie 令牌 → 反向代理到 DSH Web UI (127.0.0.1:3080)
       │      └─ HTML 注入:data-lan-device="phone" + 手机紧凑排版 CSS + randomUUID polyfill
       └─ 超限 → 429 限流页

电脑 http://127.0.0.1:3088/lan-gate/admin  → 管理页(批准/拒绝/撤销/设置访问方式)
  • 网关是独立子进程,与 DSH 主进程隔离:崩溃不影响主服务,插件停止时自动终止。
  • DSH 主 webserver 仍只监听 127.0.0.1,不暴露到局域网(官方 CLI 有意禁止 --host 0.0.0.0,因为 /api 无认证层)。只有经本网关批准、持有令牌的设备才能到达 DSH。

🚀 快速开始

方式零:dsh plugin add(标准安装,官方插件生态)

# 本地目录安装(先在仓库所在目录执行)
dsh plugin --profile web add ./dsh-mobile-gate

本仓库声明了 dsh.bundle manifest,安装后自动激活配置层,无需手写 patch。

Showing the opening section of the README — the full document lives in the repository以上为 README 开头摘要,完整文档在仓库内 · View the full README on GitHub →在 GitHub 查看完整 README →

← 上一个 Prev dsh-ha-orchestrator 下一个 Next dsh-duet →