king-bcolor/dsh-multi-tenant-projects 预览 preview

king-bcolor/dsh-multi-tenant-projects

DeepSeek Harness(DSH)的多租户项目与用户插件:按用户符号链接工作区、登录门禁、会话隔离、工作区写锁及系统提示词防护。

Project Overview项目介绍

This is a native plugin built exclusively for DeepSeek Harness (DSH) that adds multi-tenant project and user management to a single DSH instance. It binds real host directories to projects, generates per-user symlinked workspaces inside each project, and adds password-protected login to the DSH web UI to keep sessions and files isolated between multiple shared users. To install, you can run a one-line command dsh plugin --profile web add github:king-bcolor/dsh-multi-tenant-projects, since the repo ships pre-built artifacts and no local build is required. You can also pin to a specific release by appending a version tag like #v0.1.0 to the install command, as long as your Node version meets DSH’s base requirements.

After installation, you need to restart DSH and check the console logs for the confirmation message that the plugin is ready. The first step is to log in as the bootstrap admin with the default username admin and default password admin (you should change this immediately after your first login). From the admin console located in Settings → Projects & Users, you can create new projects, bind existing local directories or let the system auto-generate new workspaces, then create per-project users with unique passwords. Once users are created, they can log in and only access their own isolated workspaces and sessions.

The plugin is licensed under the permissive open-source MIT license, and it has several known limitations you should be aware of before deployment. Isolation provided by the plugin is soft rather than a hard security boundary: cwd filtering is projection-based, technically inclined users can bypass front-end guards, and agent isolation is enforced only via prompt instructions. There is only a single admin model, and no dedicated user interface for token revocation — disabling a user account will instantly invalidate all of their existing tokens. It also requires a full DSH restart after any changes to the client-side code to push updates to end-user browsers.

这是一个专为DeepSeek Harness(DSH)开发的原生插件,为单实例DSH部署提供多租户项目与用户管理能力。核心功能包括将实际工作区目录绑定为项目,为每个用户生成项目内的符号链接工作区,给Web UI添加密码登录防护,实现多个用户共享同一DSH实例时的会话与文件隔离。推荐使用dsh plugin命令行一键安装,仓库已自带预构建产物,不需要本地构建,只要你的Node版本满足DSH本身的要求即可。

典型使用流程是,管理员登录后先进入设置的「Projects & Users」控制台创建项目,可绑定已有本地目录或让系统自动生成新工作区,接着在项目下创建普通用户并分配登录密码。普通用户登录后只能访问自己工作区下的会话和文件,权限被固定为工作区写入,无法修改权限,系统也会自动注入边界规则提示Agent遵守隔离要求。该插件适合团队内部多个可信成员共享同一DSH实例的场景使用。

需要注意的是,该插件提供的是软边界隔离,不是硬安全边界,cwd过滤是查询投影,技术用户可以伪造浏览器令牌,Agent层隔离是提示级别的。如果实例暴露在公网,需要在DSH前端搭配反向代理认证、VPN等真正的安全边界。插件采用MIT许可证开源,当前为单管理员模型,没有令牌撤销UI,禁用用户即可使其所有令牌失效。

Pre-install check安装前体检Compatibility · Security兼容性 · 安全性 1 warning1 项注意
  • No license declared - all rights reserved by default; ask the author before commercial use or redistribution未声明开源许可证 —— 默认「保留所有权利」,商用或再分发前先问作者
  • 26 stars - an early-stage project星标 26,属于早期项目
DSH walks through these 9 checksDSH 会逐条核对这 9 项

Compatibility兼容性

  • DSH, Node, OS and profile requirementsDSH 版本 / Node 版本 / 操作系统 / profile 是否满足要求
  • External dependencies and runtimes (Electron / Python / Docker, ...)外部依赖与运行时(Electron / Python / Docker 等)是否齐备
  • Conflicts with installed plugins: command names, skill / tool names, ports, duplicate MCP registration与已装插件是否冲突:命令名、skill / tool 重名、端口占用、重复 MCP 注册

Security安全性

  • Repo matches the facts registered here; archived or abandoned?仓库是否与页面登记一致,是否归档或长期停更
  • Safety of preinstall / install / postinstall and install.sh / setup.ps1preinstall / install / postinstall 与 install.sh、setup.ps1 是否安全
  • curl|bash, download-then-execute, obfuscation, unrelated domains → stop immediatelycurl|bash、下载即执行、混淆代码、无关域名 → 立刻停止
  • Typosquatting or unmaintained packages among the new dependencies新增依赖里有没有 typosquatting 或无人维护的包
  • Requested permissions vs. what the feature actually needs申请了哪些权限、是否超出功能所需(filesystem / network / shell / clipboard)
  • Any sudo / admin requirement, plus uninstall and rollback是否要求 sudo / 管理员权限,以及卸载与回滚方式

Anything uncertain must be marked unknown with a note on how to confirm it. This site's signal screen is a static snapshot, not a security audit.拿不准的必须标「未知」并说明要我怎么确认。本站的信号筛查是静态快照,不能替代安全审计。

Or use CLI install (for developers)或使用命令行安装(适合开发者)

CLI Install命令行安装

dsh plugin --profile web add github:king-bcolor/dsh-multi-tenant-projects

把 king-bcolor/dsh-multi-tenant-projects 加入你的 DSH 配置(web profile)即可启用。

READMEREADME

dsh-multi-tenant-projects

简体中文 | English

Multi-tenant "Projects & Users" for a single DeepSeek Harness (DSH) instance: bind real workspace directories to projects, hand out per-user symlinked workspaces inside each project, and gate the Web UI behind password login — so several people can share one DSH deployment without seeing each other's sessions or files.

Threat model — read this first. This plugin is a soft boundary, not a hard security perimeter. The cwd filter is a query projection, browser tokens can be forged by a technical user, and the agent-layer isolation is prompt-level. For anything exposed to the public internet, put a real boundary (reverse-proxy auth, ngrok basic auth, VPN…) in front of DSH and treat this plugin as convenience isolation between trusted-ish teammates.

Features

  • Projects bound to real directories (auto-created, or bind an existing workspace path via the host-native directory picker).
  • One-shot users per project with password login; Bearer tokens with sha256 fingerprints, TTL, and instant invalidation when a user is disabled.
  • Same-name users across projects — storage key is <project>/<user>; log in as project/user when a bare name is ambiguous.
  • Per-user workspace: a real directory whose entries are symlinks to the project's files; new project entries can be re-synced (admin/sync).
  • Login gate: a full-frame login card while the guard is armed and no valid token is stored (fails open if the plugin API itself is broken).
  • Restricted UI for normal users: sidebar shows only their own cwd-bucketed sessions (with durable titles — cold sessions no longer fall back to the directory name), settings entry and workspace switcher are shadowed away, the hero picker offers only their own workspace, auto-connected on login.
  • Permission lock: every normal-user session is pinned to workspace-write and /permission switching is refused; the composer access-mode chip is frozen at Workspace Write (admins keep the full menu).
  • System-prompt guard, two layers: a host-injected 受限会话守则 section in the system prompt itself (never disclose anything outside the user's workspace, never run boundary-probing commands, refuse cross-boundary requests even when asked) plus a per-workspace AGENTS.md baseline that is auto-refreshed on sync.
  • Admin console in Settings → Projects & Users: create/list projects and users, disable users, one-shot token handoff, directory binding, sync links.
  • Sign-out badge in the sidebar footer for both admins and users.

Showing the opening section of the README — the full document lives in the repository以上为 README 开头摘要,完整文档在仓库内 · View the full README on GitHub →在 GitHub 查看完整 README →

← 上一个 Prev dsh-codex-sync 下一个 Next dsh-remote-ssh →