hdhgsysh/dsh-connect-qoder 预览 preview

hdhgsysh/dsh-connect-qoder

Plugin插件 Native原生 ⭐ 9 Notifications & Remote通知与远程

Bridge local Qoder / Qoder CN models into DeepSeek Harness

Project Overview项目介绍

This is a native model provider plugin built exclusively for DeepSeek Harness (DSH) that connects your locally logged-in Qoder model to DSH. It requires zero configuration, and Qoder models will automatically appear in DSH's model selector for you to use with your existing Qoder account quota. It supports both the domestic China version Qoder CN and the international version Qoder as separate providers, so you can install one or both, and they will keep their own separate account and quota settings. To install, you can add the repository source directly in DSH's plugin market, or install it locally via DSH CLI for development, and you will need to restart DSH after installation for changes to take effect.

This plugin reuses the existing login state from your local Qoder desktop application, so you do not need to go through an extra OAuth authentication flow to use it. It does not modify any files belonging to the Qoder application, and only reads the Qoder login information database in read-only mode. If you do not have the Qoder desktop app installed and logged in locally, you can also fall back to using an official personal access token (PAT) by setting the corresponding environment variable, and the plugin will exchange the PAT for the required job token. It is designed for developers who already have a Qoder account and want to use and manage multiple models uniformly within DSH.

The plugin does not store any of your user credentials, and any login information it reads temporarily is only stored in memory and your system's temporary directory, which is deleted immediately after the plugin process closes. It relies on Qoder's client-side APIs that are not officially open to the public, so if Qoder updates their internal interfaces, this plugin may need to be adjusted accordingly to continue working properly. This plugin is licensed under the MIT license, and it is intended only for personal study and research use. Users must comply with Qoder's terms of service, and users take all responsibility for any consequences that arise from using this plugin.

这是一个专为 DeepSeek Harness(DSH)开发的原生模型提供方插件,作用是将本机已登录的 Qoder 模型接入 DSH,零配置即可在 DSH 的模型选择器中直接使用 Qoder 的账号额度。它同时支持国内版 Qoder CN 和国际版 Qoder,会分别注册两个独立的 provider,可单独安装其中一个,也可同时安装两个并存使用。安装可通过 DSH 插件市场添加仓库源,也支持本地开发安装,安装后需重启 DSH 生效。

本插件复用 Qoder 桌面应用的现有登录状态,不需要启动额外的 OAuth 认证流程,也不会修改 Qoder 应用的任何文件,仅以只读方式打开 Qoder 的登录信息数据库。如果本地没有安装登录 Qoder 桌面应用,也可以通过设置环境变量填入官方 PAT 作为兜底方式,插件会用 PAT 换取所需的任务令牌。它适合已经拥有 Qoder 账号、想要在 DSH 中统一管理使用不同模型的开发者使用。

插件不会存储任何用户凭据,临时读取的登录信息仅存放在内存和系统临时目录中,程序关闭后会立即删除,真实密钥不会离开插件沙箱。它依赖 Qoder 未官方开放的客户端接口,如果 Qoder 更新接口,本插件可能需要同步调整才能继续使用。本插件采用 MIT 许可证,仅供个人学习研究使用,使用者需遵守 Qoder 的服务条款。

Pre-install check安装前体检Compatibility · Security兼容性 · 安全性 2 warnings2 项注意
  • No license declared - all rights reserved by default; ask the author before commercial use or redistribution未声明开源许可证 —— 默认「保留所有权利」,商用或再分发前先问作者
  • Only 9 stars - very few users, little community feedback星标只有 9,几乎没人在用,遇到问题缺少社区反馈
DSH walks through these 9 checksDSH 会逐条核对这 9 项

Compatibility兼容性

  • DSH, Node, OS and profile requirementsDSH 版本 / Node 版本 / 操作系统 / profile 是否满足要求
  • External dependencies and runtimes (Electron / Python / Docker, ...)外部依赖与运行时(Electron / Python / Docker 等)是否齐备
  • Conflicts with installed plugins: command names, skill / tool names, ports, duplicate MCP registration与已装插件是否冲突:命令名、skill / tool 重名、端口占用、重复 MCP 注册

Security安全性

  • Repo matches the facts registered here; archived or abandoned?仓库是否与页面登记一致,是否归档或长期停更
  • Safety of preinstall / install / postinstall and install.sh / setup.ps1preinstall / install / postinstall 与 install.sh、setup.ps1 是否安全
  • curl|bash, download-then-execute, obfuscation, unrelated domains → stop immediatelycurl|bash、下载即执行、混淆代码、无关域名 → 立刻停止
  • Typosquatting or unmaintained packages among the new dependencies新增依赖里有没有 typosquatting 或无人维护的包
  • Requested permissions vs. what the feature actually needs申请了哪些权限、是否超出功能所需(filesystem / network / shell / clipboard)
  • Any sudo / admin requirement, plus uninstall and rollback是否要求 sudo / 管理员权限,以及卸载与回滚方式

Anything uncertain must be marked unknown with a note on how to confirm it. This site's signal screen is a static snapshot, not a security audit.拿不准的必须标「未知」并说明要我怎么确认。本站的信号筛查是静态快照,不能替代安全审计。

Or use CLI install (for developers)或使用命令行安装(适合开发者)

CLI Install命令行安装

dsh plugin --profile web add @eghrhegpe/dsh-connect-qoder

把 hdhgsysh/dsh-connect-qoder 加入你的 DSH 配置(web profile)即可启用。

READMEREADME

DSH Connect Qoder

把本机已登录的 Qoder 模型接入 DeepSeek Harness, 零配置即可在 DSH 的模型选择器里使用你的 Qoder 账号额度。

国内版 Qoder CN 与国际版 Qoder 是两个并行的 provider(qoder-cn / qoder), 装哪个就出现哪一组模型,两个都装就两组并存,各自使用自己的账号与额度。 image

工作原理

DSH PiAiAdapter(每个区域一套)
  -> 安全 loopback shim(随机端口 + 进程内随机 secret)
  -> COSY 签名 + 自定义 base64 编码
  -> 国内版 https://gateway.qoder.com.cn/
  -> 国际版 https://api3.qoder.sh/
  -> Qoder 双层包装 SSE
  -> OpenAI SSE
  -> DSH 本地执行工具并回传结果

Qoder 不是 OpenAI 兼容端点,所以需要三样东西:

  1. COSY 签名头 —— 每个网关请求都带 Cosy-* 头与 Authorization: Bearer COSY.<payload>.<sig>, 签名是对 base64 负载、RSA 包装的 AES 密钥、时间戳、请求体与签名路径做 MD5。
  2. 置换 base64 请求体 —— 查询串里的 Encode=1 表示 JSON 体要先 base64、再按换过的字母表 逐字符替换、最后按三分之一旋转。
  3. 双层 SSE —— 每个 data: 帧是一个信封对象,它的 body 字段本身又是 JSON 字符串, 里面才是 OpenAI 风格的 chunk。

凭据来源

插件复用 Qoder 桌面应用自己的登录状态,不启动额外的 OAuth 流程,也不写入应用的文件 (凭据文件以只读方式打开)。

Qoder 把登录信息放在 Chromium OSCrypt 格式的凭据文件里(v10 + nonce + 密文 + tag,AES-256-GCM)。 新版(0.3.x)的凭据直接保存在 <userData>/auth.v1.dat,旧版(0.2.x 及更早)则放在 VS Code 风格的 state.vscdb SQLite 数据库里。两种布局都支持,新版优先尝试。 密文用的密钥保存在应用的 Local State 中,由操作系统 keystore 包裹 —— Windows 上是当前用户 作用域的 DPAPI,因此同一用户下的进程都能解开它。 Node 没有内置 DPAPI 绑定,这一步交给 PowerShell,并通过临时文件交换结果(不使用管道), 这样在禁止管道 stdio 的沙箱里同样可用。

没有桌面应用登录时,可以用官方文档的 PAT 兜底:设置 QODERCN_PAT(国内版)或 QODER_PAT(国际版),插件会用它换取 job token。

平台边界:零配置路径只在 Windows 成立。 解密链路是 PowerShell + DPAPI(Crypt32.dll), lib/ 里没有任何 macOS / Linux 解包分支——在其它平台上应用目录找得到(应用数据根目录 已按平台解析,见下),但凭据读不出来(loadCredential 返回 undefined,该区域不注册), 只剩上面的 PAT 兜底。

这不是"没有跨平台客户端",而是客户端已跨平台、插件尚未跟上:Qoder 桌面版在 macOS 12+ / Linux (.deb/.rpm) / HarmonyOS 上都有下载(qoder.com.cn/download), 但 lib/ 只实现了 Windows 这一条解密链。缺口在两处,全部登记在 docs/KNOWN_GAPS.md 第 6 条(跨平台凭据链未实现):

  1. OS keystore 封装(含 key 派生):Windows 走 DPAPI;macOS 需 Keychain(security), 且 Chromium 在 macOS 上对 encrypted_key 还要做 PBKDF2-HMAC-SHA1 派生("peanuts" 常量 + 1003 次迭代)——与 DPAPI 直解是两种算法,不是换个命令;Linux 需 libsecret(secret-tool) 或 Chromium 在 Linux 上的 peanuts 硬编码 key 兜底。
  2. 跨平台 CI 与实机验证:GitHub Actions 的 macos / ubuntu runner 可以编译并跑单测,但 Keychain 弹窗、签名打包、secret-tool 的 D-Bus session 都得在实机或 runner 上验。

Showing the opening section of the README — the full document lives in the repository以上为 README 开头摘要,完整文档在仓库内 · View the full README on GitHub →在 GitHub 查看完整 README →

← 上一个 Prev dsh-mobile-suite 下一个 Next dsh-archify →