Leon0555/dsh-lan-access 预览 preview

Leon0555/dsh-lan-access

一个DSH局域网内访问插件:让 DeepSeek Harness 可在局域网内被其他设备访问的 DSH 插件。同一局域网下,手机/平板/电脑打开浏览器即可直接访问你某台设备上的 DSH——无需 SSH、无需内网穿透,npm 一键安装。

Project Overview项目介绍

This repository is Leon0555/dsh-lan-access, a plugin built exclusively for DeepSeek Harness (DSH) that enables LAN access to DSH's web GUI from other devices on the same local network. To install the plugin, you can either pass the repository link directly to DSH for automatic installation, or install it from npm via the command dsh plugin --profile web add dsh-lan-access, which requires you to have pnpm installed globally on your system. It provides three core features: binding the DSH web server to 0.0.0.0, adding a polyfill for crypto.randomUUID to fix RPC errors when accessing over plain HTTP LAN, and automatically adapting the layout for mobile narrow screens.

After installation, you need to restart the DSH service for the changes to take effect. Once DSH is restarted, any other device connected to the same LAN can access your DSH instance by opening http://<your DSH host's LAN IP>:3080 in any standard web browser. This plugin is designed for users who need to access their local DSH instance from multiple devices, such as checking conversation progress and continuing chats on a mobile phone when away from the host computer, or sharing a single DSH instance across multiple devices on a company intranet.

The plugin follows DSH's native security design, and does not bypass DSH's restriction that configuration-related privileged interfaces can only be accessed from localhost. It explicitly states that the plugin offers no authentication for LAN access, so it should only be used on trusted internal networks like home or corporate LANs, and should not be enabled on public WiFi. Before you use the plugin after installation, you should also read the security note carefully to avoid exposing your DSH instance to unauthorized access. The project is released under the open-source MIT license, which allows free use, modification, and distribution of the code.

本仓库是Leon0555开发的dsh-lan-access,是专门为DeepSeek Harness(DSH)打造的原生插件,作用是让DSH的Web GUI可以被同一局域网内的其他设备访问。不需要SSH,也不需要内网穿透,只需要通过npm一键安装或者让DSH直接安装项目链接就能完成部署。它的核心功能包含三个部分:局域网绑定、适配明文HTTP访问的polyfill补全,以及自动适配手机窄屏排版。

它的典型使用流程是,安装完成后按照说明重启DSH服务,其他只要在同一局域网下的手机、平板或者电脑,通过浏览器访问“http://<运行DSH设备的IP地址>:3080”就能正常使用。适合需要在多设备间访问本地DSH,比如外出时用手机查看对话进度、继续对话,或者在公司内网多设备共享DSH实例的用户使用。

本插件遵循DSH原有的安全设计,不会绕过DSH对配置相关接口的本机访问限制,仅开放对话等非敏感接口给局域网访问。使用时需要注意,本插件无访问认证,仅适合家庭或公司的可信内网环境使用,公共WiFi下不要开启。本项目采用MIT许可证开源,完全免费供用户使用和修改。

Pre-install check安装前体检Compatibility · Security兼容性 · 安全性 1 note1 项提示
  • 13 stars - an early-stage project星标 13,属于早期项目
DSH walks through these 9 checksDSH 会逐条核对这 9 项

Compatibility兼容性

  • DSH, Node, OS and profile requirementsDSH 版本 / Node 版本 / 操作系统 / profile 是否满足要求
  • External dependencies and runtimes (Electron / Python / Docker, ...)外部依赖与运行时(Electron / Python / Docker 等)是否齐备
  • Conflicts with installed plugins: command names, skill / tool names, ports, duplicate MCP registration与已装插件是否冲突:命令名、skill / tool 重名、端口占用、重复 MCP 注册

Security安全性

  • Repo matches the facts registered here; archived or abandoned?仓库是否与页面登记一致,是否归档或长期停更
  • Safety of preinstall / install / postinstall and install.sh / setup.ps1preinstall / install / postinstall 与 install.sh、setup.ps1 是否安全
  • curl|bash, download-then-execute, obfuscation, unrelated domains → stop immediatelycurl|bash、下载即执行、混淆代码、无关域名 → 立刻停止
  • Typosquatting or unmaintained packages among the new dependencies新增依赖里有没有 typosquatting 或无人维护的包
  • Requested permissions vs. what the feature actually needs申请了哪些权限、是否超出功能所需(filesystem / network / shell / clipboard)
  • Any sudo / admin requirement, plus uninstall and rollback是否要求 sudo / 管理员权限,以及卸载与回滚方式

Anything uncertain must be marked unknown with a note on how to confirm it. This site's signal screen is a static snapshot, not a security audit.拿不准的必须标「未知」并说明要我怎么确认。本站的信号筛查是静态快照,不能替代安全审计。

Or use CLI install (for developers)或使用命令行安装(适合开发者)

CLI Install命令行安装

dsh plugin --profile web add dsh-lan-access

把 Leon0555/dsh-lan-access 加入你的 DSH 配置(web profile)即可启用。

READMEREADME

dsh-lan-access

让 DeepSeek Harness Web GUI 可在局域网内被其他设备访问的 DSH 插件(可信内网专用)。 同一局域网下,手机/平板/电脑打开浏览器即可直接访问你某台设备上的 DSH——无需 SSH、无需内网穿透,npm 一键安装。

npm version License

功能

  1. 局域网绑定:把 webserver 的 host 改为 0.0.0.0,手机/其他电脑可通过 http://<运行DSH设备的IP>:3080 访问(查 IP:ipconfig getifaddr en0)。

  2. crypto.randomUUID polyfill:浏览器只在安全上下文(HTTPS/localhost)暴露 crypto.randomUUID,局域网明文 HTTP 下不存在,会导致 DSH 的 RPC 全部失败 (项目/会话列表加载不出、无法添加工作区)。本插件向每次返回的 index.html 注入兜底实现(标准 UUID v4,crypto.getRandomValues 生成),任何设备的 浏览器访问都正常。

  3. 手机/窄屏自动适配(v0.1.2+):屏幕宽度 ≤820px 时自动切换为紧凑移动排版, 无需任何配置。包括:

    • 字号压缩与排版收紧(消息流、代码块、标题层级)
    • 输入框 font-size:16px,规避 iOS 聚焦自动放大
    • 按钮加大触控目标、去除点击延迟(touch-action:manipulation)
    • 弹层/对话框全屏化(100dvh + 安全区适配),模型选择等浮层固定定位防遮挡
    • 深色/浅色主题下均生效(跟随 DSH 本身)

    适配 CSS 移植自 dsh-lan-gate (MIT License),取其窄屏兜底层,仅保留排版适配,不含其网关/审批功能。

安装(DSH自己安装)

把这个项目的链接贴给DSH,让它自己安装即可。

安装(从 npm)

dsh plugin --profile web add dsh-lan-access

需要 pnpm(npm i -g pnpm)。本地开发安装可用 dsh plugin --profile web add file:/path/to/dsh-lan-access。

安装后重启服务生效:

launchctl kickstart -k gui/$(id -u)/com.dsh.web   # 如果用 launchd 常驻

卸载

dsh plugin --profile web remove dsh-lan-access

卸载后 webserver 恢复默认仅 127.0.0.1,polyfill 不再注入。

安全提醒

  • 绑定 0.0.0.0 后,同一网络内任何设备都能连接 DSH(无认证), 等于整网都能触达本机的命令执行能力。仅限家庭/公司可信内网使用, 公共 WiFi 请勿开启。
  • 建议:路由器/防火墙限制来源 IP;出外网访问请叠加 Tailscale 等隧道。

远程访问限制(安全设计,本插件有意不绕过)

DSH 把"配置平面"——**设置页、模型/Provider 管理、凭据、Agent Preset、 目录选择、llm.discoverModels(模型探测)**等接口——硬性限制为仅本机回环 (127.0.0.1)可访问。即使本插件将 Web 服务绑定到 0.0.0.0,这些接口从 局域网 IP 访问仍会返回 HTTP 403(如"加载提供方目录失败: ... HTTP 403")。

这是 DSH 官方刻意的安全边界(dsh-client-connection 的 PRIVILEGED_METHODS): trustedHosts 白名单只是 DNS 反绑定栅栏,不是认证;在真正的认证层出现 之前,设置/凭据域必须保持仅本机可访问。

本插件不绕过这个栅栏,也不提供代理/端口转发去改写请求头——那会把设置与 凭据侦察能力暴露给局域网内任何设备,违背 DSH 的安全设计。

远程(局域网)可用 vs 不可用

Showing the opening section of the README — the full document lives in the repository以上为 README 开头摘要,完整文档在仓库内 · View the full README on GitHub →在 GitHub 查看完整 README →

← 上一个 Prev dsh-replay 下一个 Next dsh-web-fetch-enhanced →