BotonJ/dsh-remote-link

DeepSeek Harness 的带认证远程网关:支持二维码/HMAC 配对、Cookie 会话、mDNS、fork_session 工具。零依赖插件。

Project Overview项目介绍

dsh-remote-link is a native plugin built exclusively for DeepSeek Harness (DSH) that securely exposes DSH’s official local Web UI to a local area network, enabling remote control of the desktop DSH agent from a mobile device via QR code pairing. It also adds a fork_session tool that lets the model fork existing conversation contexts to explore alternative approaches without disrupting the current session. The plugin can be installed directly through DSH’s built-in plugin manager, either from a local clone of the repository or directly from its GitHub address, and requires no core modifications to DSH or any additional runtime dependencies.

After installation, when you start DSH, the plugin outputs a one-time ASCII QR code and a 6-digit short code directly to the startup log. You can scan the QR code with your mobile phone’s browser to connect and open the DSH UI immediately with no extra authentication steps. If scanning isn’t an option, you can navigate to the pairing page on any mobile or desktop device connected to the same network and enter the short code to complete pairing. This tool is ideal for users who want to check or interact with their DSH agent on the go from their phone, without needing to stay at their desktop computer.

dsh-remote-link is released under the permissive MIT open-source license, and while it is built for DSH, it can also be run independently as an authentication reverse proxy for MiMo Code to expose MiMo’s local UI to mobile devices as well. It implements multiple layered security measures, including HMAC challenge-response authentication, HttpOnly secure cookies, rate limiting for authentication attempts, and automatic expiration of idle or inactive devices. There is one known unresolved limitation: local network sniffers can steal session cookies to take over an active connection, which will be addressed in the upcoming v2 release that adds TLS relay support.

这是一个专为 DeepSeek Harness (DSH) 开发的原生插件,作用是将 DSH 的官方 Web UI 安全暴露到局域网,用户可以用手机扫码直接遥控电脑上的本地 agent,同时还为模型新增了 fork_session 会话分叉工具。它对 DSH 零核心改动,自身也零运行时依赖,可通过 DSH 内置的插件命令直接安装,支持从本地目录或 GitHub 仓库添加。

安装完成后,启动日志会直接输出一次性配对二维码(ASCII 格式)和 6 位短码。用户可以直接用手机扫码,无弹窗打开 DSH 官方 UI 进行操作;如果无法扫码,也可以在任意设备打开配对页面输入短码完成连接。它适合需要通过移动设备远程操控电脑上 DSH 代理的用户,还支持当代理等待用户审批且无已连接设备时推送通知提醒。

它采用 MIT 许可开源,除了支持 DSH 外,还可独立作为认证反代服务给 MiMo Code 使用,把 MiMo Code 也变成手机可遥控的代理。它具备完整的安全机制,包括 HMAC 挑战应答认证、HttpOnly Cookie 会话和暴力破解阻尼。目前已知局限是局域网嗅探者可复制 Cookie 接管会话,该问题将在未来 v2 版本的 TLS 中继功能中修复。

Pre-install check安装前体检Compatibility · Security兼容性 · 安全性 1 warning1 项注意
  • Only 5 stars - very few users, little community feedback星标只有 5,几乎没人在用,遇到问题缺少社区反馈
DSH walks through these 9 checksDSH 会逐条核对这 9 项

Compatibility兼容性

  • DSH, Node, OS and profile requirementsDSH 版本 / Node 版本 / 操作系统 / profile 是否满足要求
  • External dependencies and runtimes (Electron / Python / Docker, ...)外部依赖与运行时(Electron / Python / Docker 等)是否齐备
  • Conflicts with installed plugins: command names, skill / tool names, ports, duplicate MCP registration与已装插件是否冲突:命令名、skill / tool 重名、端口占用、重复 MCP 注册

Security安全性

  • Repo matches the facts registered here; archived or abandoned?仓库是否与页面登记一致,是否归档或长期停更
  • Safety of preinstall / install / postinstall and install.sh / setup.ps1preinstall / install / postinstall 与 install.sh、setup.ps1 是否安全
  • curl|bash, download-then-execute, obfuscation, unrelated domains → stop immediatelycurl|bash、下载即执行、混淆代码、无关域名 → 立刻停止
  • Typosquatting or unmaintained packages among the new dependencies新增依赖里有没有 typosquatting 或无人维护的包
  • Requested permissions vs. what the feature actually needs申请了哪些权限、是否超出功能所需(filesystem / network / shell / clipboard)
  • Any sudo / admin requirement, plus uninstall and rollback是否要求 sudo / 管理员权限,以及卸载与回滚方式

Anything uncertain must be marked unknown with a note on how to confirm it. This site's signal screen is a static snapshot, not a security audit.拿不准的必须标「未知」并说明要我怎么确认。本站的信号筛查是静态快照,不能替代安全审计。

Or use CLI install (for developers)或使用命令行安装(适合开发者)

CLI Install命令行安装

dsh plugin --profile web add github:BotonJ/dsh-remote-link

把 BotonJ/dsh-remote-link 加入你的 DSH 配置(web profile)即可启用。

READMEREADME

dsh-remote-link

Awesome DSH Plugin

把 DeepSeek Harness(DSH)的官方 Web UI 安全地暴露到局域网——手机扫码即遥控电脑上的 agent——并给模型增加 fork_session 会话分叉工具。零核心改动、零运行时依赖。

v1.6:链路保活 + 状态页——DSH 事件下行流(/api/events.mux)没有任何心跳,空闲连接会被隧道边缘/运营商 NAT 静默收割,手机端触发全量 resync。网关现按需向浏览器注入 WS ping(仅在帧边界、仅空闲时),从根源避免断连;/status 状态页实时展示每条连接的 RTT 与保活计数(调研与设计见 docs/LINK-KEEPALIVE-DESIGN.md)。

v1.6.1:死腿清理 + 连接身份 + 全链路健康——连续 3 个 ping 无 pong 的半开连接被主动关闭(客户端立刻重连,不再干等 TCP 超时);/status 的每条连接标注设备身份(配对 cookie → 设备名 + 来源 IP)、上游健康(最近成功 + 最近 10 条代理错误)、隧道连接器心跳年龄(cf-tunnel.sh 每 30s 落盘,配置 tunnelHeartbeatFile 读取)。

v1.6.2:也适用于 MiMo Code——网关本质是"认证 + 反代",上游不挑食。mimo/ 目录提供恢复移动端 Web UI 的 2 文件补丁,独立运行器 runner-gateway.mjs 一条命令把 MiMo Code 变成手机可遥控的 agent(见下文"也适用于 MiMo Code")。

v1.6.3:宿主遥测——/status 的"上游健康"从"HTTP 服务器活着"升级到"DSH 全栈活着":网关以官方客户端同款信封调用 /api/host.describe(必须穿过 webserver → ApiProxy → 宿主才能返回,顺带量出 RPC 延迟、取回 model/版本/会话数),并订阅 /api/events.host 事件流实时跟踪 agent 忙闲。非 DSH 上游(如 MiMo,其兜底 UI 路由对一切路径回 200 HTML)会被形状判定自动识别并静默,不产生噪音。

v1.7 候选已实现(待审核):审批离线推送 + 长期恢复码——① notify 配置 Bark/ntfy/webhook:agent 等待审批/回答且无任何已连接浏览器时推一条"该去处理了"的门铃(仅通知不含任何秘密,按 ID 去重 + 60s 冷却;有浏览器在线则静默);② pairing.recoveryCode:所有设备丢失时用长期恢复码在 /pair 页自助恢复接入(SHA-256 摘要常时比较,每次恢复注册为可吊销设备,≥16 字符熵下限)。

v1.5:QR 一次性配对 + HMAC 挑战-响应 + HttpOnly Cookie 会话 + 设备注册表(v1 的 ?token= 明文折衷已删除,设计见 docs/PAIRING-DESIGN.md)。

手机扫码(→ /pair#p=sid.secret, secret 留在 fragment)
   → GET /pair/challenge?sid  → {nonce, ts}
   → proof = HMAC(secret, sid|nonce|ts)
   → POST /pair/verify        → Set-Cookie rls=<token> (HttpOnly, SameSite=Strict, 30d)
   → 官方 UI / /api RPC / WS 事件流全部走 cookie,无密码无弹窗

为什么这样设计

  • 主 webserver 保持 loopback:DSH 官方 CLI 明确拒绝 --host 0.0.0.0("would expose remote code execution to the network")。本插件是"被认可的远程暴露方式":网关在独立端口做认证,反代到 loopback。
  • 官方前端直接复用:不做自己的 UI(dsh-desktop 也是 Electron 壳 loadURL 官方 UI),聊天框就是遥控器。
  • ?token= 查询参数认证:浏览器 WebSocket/EventSource API 无法携带 Authorization 头,官方 UI 的事件流(/api/events.mux)在手机上必须有这条通路(与 MiMo 移动端方案一致)。

安装

dsh plugin --profile web add ./dsh-remote-link     # 本地目录
# 或 dsh plugin --profile web add github:<you>/dsh-remote-link

Showing the opening section of the README — the full document lives in the repository以上为 README 开头摘要,完整文档在仓库内 · View the full README on GitHub →在 GitHub 查看完整 README →

← 上一个 Prev dsh-liang-slider 下一个 Next dsh-sleep-send →