Mzy123l/dsh-plugin-remote-access

Desktop桌面端 Native原生 ⭐ 2 MIT Notifications & Remote通知与远程

给 DeepSeek Harness(DSH)桌面版用的插件:把本机 DSH 的网页界面只开放给你指定的网段 (默认 Tailscale 的 100.64.0.0/10),于是手机或另一台电脑也能用上它。

catalog descriptioncatalog 简介 / catalog description:为 DeepSeek Harness 桌面版提供「限网段 + 可选数字密码」的远程访问入口

Project Overview项目介绍

dsh-plugin-remote-access is a native plugin built for the DeepSeek Harness (DSH) desktop edition that exposes the local DSH web UI only to caller-approved network ranges, deliberately avoiding a public 0.0.0.0 bind. It is packaged as a cordis bundle, shipped on npm as dsh-plugin-remote-access@1.2.0, and installed through DSH's Settings → Plugins page by entering the npm name, github:Mzy123l/dsh-plugin-remote-access, or an absolute local path; the CLI equivalent is dsh plugin --profile desktop add <source>, and install.ps1 only fetches the source tree to %LOCALAPPDATA%\dsh-plugins\dsh-plugin-remote-access so that DSH itself performs the actual install step. Renaming from the abandoned dsh-remote-access-cidr (stuck at 1.0.0) requires users to remove the old entry from the Plugins list first, because bundles load by package name and may also wipe the id: remote-access config block inside cordis.patch.yml.

In normal use the operator configures an 允许的网段 allow-list (defaulting to Tailscale's 100.64.0.0/10), restarts DSH once after the install, and reads <DSH_HOME>\remote-access-url.txt (default %USERPROFILE%\.dsh, mode 0600) for the token-bearing URL plus the plain mobile address. Visitors either open http://<host>:<port>/?token=… once so DSH can mint a 30-day signed cookie, or set an 访问密码 of 4–12 alphanumerics (case-sensitive; other characters are rejected at save time with an inline rule hint) and enter it once from a phone. A single wrong password immediately writes that address into 排除的网段 as a /32, where it always returns 403; the cookie's secret lives separately in <DSH_HOME>\remote-access-secret, so changing the password never kicks existing devices off, and deleting that file forces re-authentication.

The 远程UI布局 setting selects phone, desktop, or auto per remote page only, and a collapsible UI 设置 sub-menu mirrors DSH's official 外观, 字号, 工作步骤展示, 显示代码工作视图, 性能与用量 preferences into remote pages (with default explicitly reapplying the host defaults) while touching no pixel of the local page. index.js uses only node: built-ins, but client.js and check-config-schema.mjs rely on Schemastery shipped inside the DSH installation; edits to client.js only need a page reload, while new fields in index.js require restarting DSH. The accompanying Android shell at android/dsh-remote-1.1.1.apk (app name DSH, self-signed CN=DSH Remote) only requests INTERNET and ACCESS_NETWORK_STATE, the project is MIT licensed, and the status file contains credentials equivalent to local machine access, so it must not be shared.

dsh-plugin-remote-access 是面向 DeepSeek Harness(DSH)桌面版的原生插件,按网段开放本地 DSH 网页界面,避开 0.0.0.0 暴露。它通过 cordis bundle 包装载,随 package.json 一起发布到 npm(dsh-plugin-remote-access@1.2.0),也可通过 DSH「设置 → 插件 → 添加插件」填 github:Mzy123l/dsh-plugin-remote-access 或绝对路径安装;命令行走 dsh plugin --profile desktop add,还能用 install.ps1 把源码拉到 %LOCALAPPDATA%\dsh-plugins\dsh-plugin-remote-access 后由 DSH 自己装载。

典型流程是给本机 DSH 设 允许的网段(默认 Tailscale 的 100.64.0.0/10),启动后写一份 <DSH_HOME>\remote-access-url.txt 自诊断文件,里面给出带令牌网址和裸地址。访问者要么用带 ?token=… 的 URL,要么先在 访问密码 写 4–12 位数字字母,cookie 30 天免密;错一次该地址 /32 写进 排除的网段。远程UI布局 可选 phone / desktop / auto,布局引擎只对远程页注入样式,UI 设置 子菜单把官方五项偏好复制到远程页面。

依赖上 index.js 零依赖仅用 node: 内置,client.js 依赖 DSH 自带 Schemastery;设置项保存走 profile 的 cordis.patch.yml,变更热重载,但 client.js 改完需刷新页面、index.js 改完需重启 DSH。包在 npm 上的旧名 dsh-remote-access-cidr 停在 1.0.0、还另有同名别人的包,请勿再用;状态文件含访问令牌视为本机权限不要外传。

Pre-install check安装前体检Compatibility · Security兼容性 · 安全性 2 warnings2 项注意
  • Only 2 stars - very few users, little community feedback星标只有 2,几乎没人在用,遇到问题缺少社区反馈
  • Desktop client: installation downloads an executable - verify the publisher and checksums桌面客户端:安装会下载可执行文件,请核对发布者与校验和
DSH walks through these 9 checksDSH 会逐条核对这 9 项

Compatibility兼容性

  • DSH, Node, OS and profile requirementsDSH 版本 / Node 版本 / 操作系统 / profile 是否满足要求
  • External dependencies and runtimes (Electron / Python / Docker, ...)外部依赖与运行时(Electron / Python / Docker 等)是否齐备
  • Conflicts with installed plugins: command names, skill / tool names, ports, duplicate MCP registration与已装插件是否冲突:命令名、skill / tool 重名、端口占用、重复 MCP 注册

Security安全性

  • Repo matches the facts registered here; archived or abandoned?仓库是否与页面登记一致,是否归档或长期停更
  • Safety of preinstall / install / postinstall and install.sh / setup.ps1preinstall / install / postinstall 与 install.sh、setup.ps1 是否安全
  • curl|bash, download-then-execute, obfuscation, unrelated domains → stop immediatelycurl|bash、下载即执行、混淆代码、无关域名 → 立刻停止
  • Typosquatting or unmaintained packages among the new dependencies新增依赖里有没有 typosquatting 或无人维护的包
  • Requested permissions vs. what the feature actually needs申请了哪些权限、是否超出功能所需(filesystem / network / shell / clipboard)
  • Any sudo / admin requirement, plus uninstall and rollback是否要求 sudo / 管理员权限,以及卸载与回滚方式

Anything uncertain must be marked unknown with a note on how to confirm it. This site's signal screen is a static snapshot, not a security audit.拿不准的必须标「未知」并说明要我怎么确认。本站的信号筛查是静态快照,不能替代安全审计。

Or use CLI install (for developers)或使用命令行安装(适合开发者)

CLI Install命令行安装

dsh plugin --profile desktop add dsh-plugin-remote-access

把 Mzy123l/dsh-plugin-remote-access 加入你的 DSH 配置(web profile)即可启用。

READMEREADME

dsh-plugin-remote-access

给 DeepSeek Harness(DSH)桌面版用的插件:把本机 DSH 的网页界面只开放给你指定的网段 (默认 Tailscale 的 100.64.0.0/10),于是手机或另一台电脑也能用上它。

  • 不绑 0.0.0.0:只监听「允许网段」里属于本机的地址,网段外的对端一律 403。
  • 不写死地址:网段、监听地址、端口、上游、落地文件全是配置项。
  • 两种进入方式:复制带令牌的网址;或者设一个密码,手机开裸地址输一次(之后 30 天免密)。
  • 手机界面能看:「远程UI布局」可选手机 / 电脑 / 自动;手机布局只作用于远程页面,本机界面一个像素都不动。
  • 手机上的官方界面偏好能留下来:「UI 设置」把「通用设置」里的外观 / 字号 / 工作步骤展示 / 显示代码工作视图 / 性能与用量存进本插件的配置(默认「出厂值」=不干预官方默认),远程页面每次打开都重新套一遍 —— 官方那几项在手机上是「改完刷新即还原」的。
  • 在设置页里改:保存即热重载(原地关掉旧监听、按新参数重开),不用重启 DSH。
  • 失败可见:无论成功失败都会写一份自诊断文件,看不到 DSH 日志时也能定位。

安装

三种方式,选一种即可;装完重启一次 DSH。

① 插件页(推荐) —— 打开 DSH →「设置 → 插件 → 添加插件」,填下面任一:

填什么 从哪里装
dsh-plugin-remote-access 从 npm(1.2.0 起已发布,装起来最快)
github:Mzy123l/dsh-plugin-remote-access 直接从 GitHub(要与仓库同步的最新代码时)
本机某个目录的绝对路径 自己 clone / 下载下来时

⚠️ npm 上那两个旧名字 —— dsh-remote-access-cidr(我们自己发的,停在 1.0.0)和 dsh-remote-access(别人的包)—— 都别再用来安装。当前名字是 dsh-plugin-remote-access: https://www.npmjs.com/package/dsh-plugin-remote-access。 (页面上那个 0.0.0-stage 是 npm 给新包名自动建的占位版本,latest 指向 1.2.0,不用管它。)

📛 改名(1.2.0):dsh-remote-access-cidr → dsh-plugin-remote-access。 bundle 的插件行是按包名装载的,所以旧来源装的那份不会自己跟过来:到「设置 → 插件」里把旧条目 移除,再按新名字添加一次。移除有可能一并清掉 profile 里 cordis.patch.yml 中 id: remote-access 那一行的 config:(网段 / 密码 / UI 设置都在里面)—— 想留参数,先把它抄下来,装好再粘回去。

② 命令行(等价于插件页那一步;DSH 正在运行时 profile 写锁会占住):

dsh plugin --profile desktop add dsh-plugin-remote-access
# 想跟仓库最新代码:dsh plugin --profile desktop add github:Mzy123l/dsh-plugin-remote-access
# CLI 若不认这两种写法,就填本机目录的绝对路径

③ GitHub 一键取代码 —— 想把源码放到本机再装:

irm https://raw.githubusercontent.com/Mzy123l/dsh-plugin-remote-access/main/install.ps1 | iex

脚本只负责把代码取到一个固定目录(默认 %LOCALAPPDATA%\dsh-plugins\dsh-plugin-remote-access), 装的动作仍然交给 DSH 自己(插件页填那个目录)。需要代理时:

$s = irm https://raw.githubusercontent.com/Mzy123l/dsh-plugin-remote-access/main/install.ps1
& ([scriptblock]::Create($s)) -Proxy http://127.0.0.1:7890

为什么不一步装完:DSH 的插件安装(写 profile 的 package.json / cordis.patch.yml、跑包管理器) 只能由 DSH 自己做(插件页,或让 agent 用 plugin_manager 工具),手工改 profile 容易把它弄坏。

Showing the opening section of the README — the full document lives in the repository以上为 README 开头摘要,完整文档在仓库内 · View the full README on GitHub →在 GitHub 查看完整 README →

← 上一个 Prev dsh-https-fix 下一个 Next dsh-proactive →