nonmean/dsh-lan-access
为DeepSeek Harness网页插件添加局域网访问功能
Project Overview项目介绍
dsh-lan-access is a native plugin built exclusively for DeepSeek Harness (DSH) that adds a toggle switch for LAN access to DSH's web GUI settings panel. It replaces the manual process of modifying cordis.patch.yml to enable LAN access, and is verified to work with DSH v0.1.6-alpha.2 and newer versions. You can install it directly via DSH's built-in plugin CLI by running the install command from the GitHub repo, and no build step or modification to the core DSH source code is required. When enabled, the DSH web server binds to 0.0.0.0 allowing other devices on the same local network to access the full authenticated DSH interface.
After installation and a quick restart of the DSH web service, you can find the LAN access toggle under the Settings → General menu. When you flip the toggle on, the plugin will display the LAN IP address of your DSH host machine with a copy button, and automatically restart the web server to bind to the new address. To access DSH from another LAN device, you just need to open the full copied URL that includes the per-process authentication token required for login. All core DSH features like chat, tool calling, and workspace management work fully from a remote LAN device, and your toggle preference is persisted across DSH restarts.
By default, LAN access is turned off, matching DSH's default security posture that only allows loopback connections. You should only enable this feature on a trusted local network, as opening DSH to untrusted networks can expose your agent and tools to unauthorized access. A small number of native host features, like picking directories and opening local file paths, remain restricted to loopback connections even when this plugin is enabled. The project is open source under the MIT license, and local development can be done with standard pnpm commands to build and typecheck code changes.
这是一个专为 DeepSeek Harness (DSH) 开发的原生插件,会在 DSH 的设置界面「设置 → 通用」中添加一个「局域网访问」切换开关,替代过去需要手动修改 cordis.patch.yml 的操作。开启后,DSH 的网页 GUI 会绑定 0.0.0.0,允许同一局域网内的其他设备通过带认证令牌的链接访问完整的 DSH 功能;关闭则恢复默认的 127.0.0.1 回环绑定。
该插件可通过 DSH 内置的插件命令直接安装,预构建产物已提交至仓库,无需本地执行构建步骤,也不需要修改 DSH 源码仓库。安装后,只需重启 DSH 网页服务即可生效,用户的开启/关闭选择会持久化保存在 DSH 的设置文件中,重启 DSH 进程后也会自动应用。适合需要在同一局域网内不同设备访问 DSH 的用户使用。
插件默认关闭局域网访问,符合 DSH 安全默认规范。仅建议在可信任的局域网环境中开启,暴露给公网会带来安全风险。目前部分主机原生功能如选择目录、打开本地路径仍仅支持回环访问,其余聊天、工具调用、工作区管理功能均可正常在局域网远程设备上使用。项目采用 MIT 许可开源。
请帮我安装这个 DSH 插件。安装前先完成【兼容性检查 + 安全性检查】,检查通过再动手。
插件:dsh-lan-access(nonmean/dsh-lan-access)
仓库:https://github.com/nonmean/dsh-lan-access
本站详情页:https://www.yhbd.top/plugins/nonmean-dsh-lan-access/
本站登记:类型 plugin · 归类 原生 DSH 插件 · 许可证 MIT · ⭐ 2 · 最近提交 2026-09-28 · 主语言 TypeScript
按下面顺序执行,每步先把结论告诉我,再进入下一步:
【1 兼容性检查】
① 我这边:DSH 版本、Node 版本、操作系统、当前 profile(web / desktop)。
② 读它的 README、package.json、插件 manifest,列出它要求的 DSH 版本 / Node 版本 / 操作系统 / 外部依赖 / 需要另外先装的运行时。
③ 逐条比对,结论只写「满足 / 不满足 / 未知」三种;不满足的给出可行替代方案。
④ 检查是否和我已装的插件冲突:命令名重复、skill / tool 重名、端口占用、重复注册的 MCP server。
【2 安全性检查】
① 仓库可信度:和上面「本站登记」是否一致;star / fork 数、创建时间、最近提交,是否归档或长期停更。
② 安装脚本:逐行看 package.json 的 preinstall / install / postinstall,以及 install.sh、setup.ps1 之类脚本。出现 curl|bash、下载后直接执行、混淆代码、访问与插件功能无关的域名,立刻停下来告诉我,不要继续装。
③ 依赖:列出新增依赖,标出无人维护、或与知名包拼写近似的可疑包(typosquatting)。
④ 权限与副作用:它会读写哪些目录、访问哪些域名、需要哪些 DSH 权限(filesystem / network / shell / clipboard 等),以及怎么卸载和回滚。
⑤ 如果它要求 sudo / 管理员权限,或权限明显超出功能所需,先停下来问我。
【3 安装】
上面两步没有「不满足」和「高危项」时才执行;用官方推荐方式安装,不要自行提权。
【4 汇报】
用表格输出:检查项 / 结论 / 依据 / 是否需要我决策。拿不准的一律写「未知」并说明要我怎么确认——不要猜,也不要替我决定。
Send this message to DSH in your current session: it verifies compatibility and security first (answering met / not met / unknown item by item) and only installs once everything checks out — it will stop and ask you if it finds a high-risk item. The box scrolls; the copy is the full prompt. CLI install commands may not be accurate across systems, so DSH is the safer route.把上面这条消息直接发给当前会话里的 DSH:它会先核对兼容性与安全性(逐条给「满足 / 不满足 / 未知」),确认没问题再安装,有高危项会停下来问你。框内可滚动,复制到的是完整提示词;安装命令不一定准确,发给 DSH 更稳。
- Only 2 stars - very few users, little community feedback星标只有 2,几乎没人在用,遇到问题缺少社区反馈
DSH walks through these 9 checksDSH 会逐条核对这 9 项
Compatibility兼容性
- DSH, Node, OS and profile requirementsDSH 版本 / Node 版本 / 操作系统 / profile 是否满足要求
- External dependencies and runtimes (Electron / Python / Docker, ...)外部依赖与运行时(Electron / Python / Docker 等)是否齐备
- Conflicts with installed plugins: command names, skill / tool names, ports, duplicate MCP registration与已装插件是否冲突:命令名、skill / tool 重名、端口占用、重复 MCP 注册
Security安全性
- Repo matches the facts registered here; archived or abandoned?仓库是否与页面登记一致,是否归档或长期停更
- Safety of preinstall / install / postinstall and install.sh / setup.ps1preinstall / install / postinstall 与 install.sh、setup.ps1 是否安全
- curl|bash, download-then-execute, obfuscation, unrelated domains → stop immediatelycurl|bash、下载即执行、混淆代码、无关域名 → 立刻停止
- Typosquatting or unmaintained packages among the new dependencies新增依赖里有没有 typosquatting 或无人维护的包
- Requested permissions vs. what the feature actually needs申请了哪些权限、是否超出功能所需(filesystem / network / shell / clipboard)
- Any sudo / admin requirement, plus uninstall and rollback是否要求 sudo / 管理员权限,以及卸载与回滚方式
Anything uncertain must be marked unknown with a note on how to confirm it. This site's signal screen is a static snapshot, not a security audit.拿不准的必须标「未知」并说明要我怎么确认。本站的信号筛查是静态快照,不能替代安全审计。
Or use CLI install (for developers)或使用命令行安装(适合开发者)
CLI Install命令行安装
dsh plugin --profile web add git+https://github.com/nonmean/dsh-lan-access.git
把 nonmean/dsh-lan-access 加入你的 DSH 配置(web profile)即可启用。
READMEREADME
dsh-lan-access
A DeepSeek Harness web plugin that adds a LAN access toggle to the DSH
Settings shell (Settings → General). It replaces the manual cordis.patch.yml
webserver override:
Tested with DeepSeek Harness
v0.1.7-rc.2— this plugin is verified runnable against that harness version.
- On — the web GUI binds
0.0.0.0, so other machines on the same network can open it athttp://<LAN-IP>:3080/?token=….dsh webprints the full URL (with the per-process?token=launch token) for the LAN address when it starts — a fresh LAN browser needs that token in the URL to authenticate. The /api trust fence is updated live, so the browser on a LAN machine works fully (chat, tools, workspace). - Off — the GUI binds
127.0.0.1again (loopback only — the safe default).
Screenshots
The DSH web GUI opened from another machine on the same network
(http://192.168.0.101:3080):

The LAN access toggle in Settings → General, showing the address other devices can open:

How it works
| Half | File | Role |
|---|---|---|
| Host | src/index.ts |
Owns a plugin-local persisted flag ($DSH_HOME/lan-access.json), the fenced /lan-access JSON route (GET state / POST set), the bind controller, and the lanAccess bind-host service. The webserver row's composed host expression reads that service, so every webserver (re)start — boot, toggle, or a post-boot user-patch re-apply — converges to the persisted setting. A toggle restarts the webserver fiber only when the bind differs, using fiber.update(config, noSave): the no-save path keeps the composed tree out of cordis.yml, which would otherwise trigger an HMR subtree reload. |
| Client | src/client/ |
Registers the General-settings row (settings.general.item, order 15) with a native checkbox switch, the LAN URLs (primary first, all live NIC addresses shown, copy button), zh/en copy, and restart-tolerant polling. |
The route fence accepts loopback or the deployment's trusted authorities, read live from the connection row's resolved config — the same boundary the /api gateway uses. Cross-site requests are refused.
Showing the opening section of the README — the full document lives in the repository以上为 README 开头摘要,完整文档在仓库内 · View the full README on GitHub →在 GitHub 查看完整 README →
xmanrui/dsh-im
tencent-connect/dsh-qqbot
flymysql/dsh-remote
whiteguo233/dsh-openbiliclaw
omdsh-dev/dsh-lark
hanshanyike/dsh-yolo
THEWOLFWALKER/dsh-notifier