nonmean/dsh-lan-access 预览 preview

nonmean/dsh-lan-access

Plugin插件 Native原生 ⭐ 2 MIT Notifications & Remote通知与远程

为DeepSeek Harness网页插件添加局域网访问功能

Project Overview项目介绍

dsh-lan-access is a native plugin built exclusively for DeepSeek Harness (DSH) that adds a toggle switch for LAN access to DSH's web GUI settings panel. It replaces the manual process of modifying cordis.patch.yml to enable LAN access, and is verified to work with DSH v0.1.6-alpha.2 and newer versions. You can install it directly via DSH's built-in plugin CLI by running the install command from the GitHub repo, and no build step or modification to the core DSH source code is required. When enabled, the DSH web server binds to 0.0.0.0 allowing other devices on the same local network to access the full authenticated DSH interface.

After installation and a quick restart of the DSH web service, you can find the LAN access toggle under the Settings → General menu. When you flip the toggle on, the plugin will display the LAN IP address of your DSH host machine with a copy button, and automatically restart the web server to bind to the new address. To access DSH from another LAN device, you just need to open the full copied URL that includes the per-process authentication token required for login. All core DSH features like chat, tool calling, and workspace management work fully from a remote LAN device, and your toggle preference is persisted across DSH restarts.

By default, LAN access is turned off, matching DSH's default security posture that only allows loopback connections. You should only enable this feature on a trusted local network, as opening DSH to untrusted networks can expose your agent and tools to unauthorized access. A small number of native host features, like picking directories and opening local file paths, remain restricted to loopback connections even when this plugin is enabled. The project is open source under the MIT license, and local development can be done with standard pnpm commands to build and typecheck code changes.

这是一个专为 DeepSeek Harness (DSH) 开发的原生插件,会在 DSH 的设置界面「设置 → 通用」中添加一个「局域网访问」切换开关,替代过去需要手动修改 cordis.patch.yml 的操作。开启后,DSH 的网页 GUI 会绑定 0.0.0.0,允许同一局域网内的其他设备通过带认证令牌的链接访问完整的 DSH 功能;关闭则恢复默认的 127.0.0.1 回环绑定。

该插件可通过 DSH 内置的插件命令直接安装,预构建产物已提交至仓库,无需本地执行构建步骤,也不需要修改 DSH 源码仓库。安装后,只需重启 DSH 网页服务即可生效,用户的开启/关闭选择会持久化保存在 DSH 的设置文件中,重启 DSH 进程后也会自动应用。适合需要在同一局域网内不同设备访问 DSH 的用户使用。

插件默认关闭局域网访问,符合 DSH 安全默认规范。仅建议在可信任的局域网环境中开启,暴露给公网会带来安全风险。目前部分主机原生功能如选择目录、打开本地路径仍仅支持回环访问,其余聊天、工具调用、工作区管理功能均可正常在局域网远程设备上使用。项目采用 MIT 许可开源。

Pre-install check安装前体检Compatibility · Security兼容性 · 安全性 1 warning1 项注意
  • Only 2 stars - very few users, little community feedback星标只有 2,几乎没人在用,遇到问题缺少社区反馈
DSH walks through these 9 checksDSH 会逐条核对这 9 项

Compatibility兼容性

  • DSH, Node, OS and profile requirementsDSH 版本 / Node 版本 / 操作系统 / profile 是否满足要求
  • External dependencies and runtimes (Electron / Python / Docker, ...)外部依赖与运行时(Electron / Python / Docker 等)是否齐备
  • Conflicts with installed plugins: command names, skill / tool names, ports, duplicate MCP registration与已装插件是否冲突:命令名、skill / tool 重名、端口占用、重复 MCP 注册

Security安全性

  • Repo matches the facts registered here; archived or abandoned?仓库是否与页面登记一致,是否归档或长期停更
  • Safety of preinstall / install / postinstall and install.sh / setup.ps1preinstall / install / postinstall 与 install.sh、setup.ps1 是否安全
  • curl|bash, download-then-execute, obfuscation, unrelated domains → stop immediatelycurl|bash、下载即执行、混淆代码、无关域名 → 立刻停止
  • Typosquatting or unmaintained packages among the new dependencies新增依赖里有没有 typosquatting 或无人维护的包
  • Requested permissions vs. what the feature actually needs申请了哪些权限、是否超出功能所需(filesystem / network / shell / clipboard)
  • Any sudo / admin requirement, plus uninstall and rollback是否要求 sudo / 管理员权限,以及卸载与回滚方式

Anything uncertain must be marked unknown with a note on how to confirm it. This site's signal screen is a static snapshot, not a security audit.拿不准的必须标「未知」并说明要我怎么确认。本站的信号筛查是静态快照,不能替代安全审计。

Or use CLI install (for developers)或使用命令行安装(适合开发者)

CLI Install命令行安装

dsh plugin --profile web add git+https://github.com/nonmean/dsh-lan-access.git

把 nonmean/dsh-lan-access 加入你的 DSH 配置(web profile)即可启用。

READMEREADME

dsh-lan-access

A DeepSeek Harness web plugin that adds a LAN access toggle to the DSH Settings shell (Settings → General). It replaces the manual cordis.patch.yml webserver override:

Tested with DeepSeek Harness v0.1.7-rc.2 — this plugin is verified runnable against that harness version.

  • On — the web GUI binds 0.0.0.0, so other machines on the same network can open it at http://<LAN-IP>:3080/?token=…. dsh web prints the full URL (with the per-process ?token= launch token) for the LAN address when it starts — a fresh LAN browser needs that token in the URL to authenticate. The /api trust fence is updated live, so the browser on a LAN machine works fully (chat, tools, workspace).
  • Off — the GUI binds 127.0.0.1 again (loopback only — the safe default).

Screenshots

The DSH web GUI opened from another machine on the same network (http://192.168.0.101:3080):

DSH web GUI opened over LAN

The LAN access toggle in Settings → General, showing the address other devices can open:

Settings → General LAN access toggle

How it works

Half File Role
Host src/index.ts Owns a plugin-local persisted flag ($DSH_HOME/lan-access.json), the fenced /lan-access JSON route (GET state / POST set), the bind controller, and the lanAccess bind-host service. The webserver row's composed host expression reads that service, so every webserver (re)start — boot, toggle, or a post-boot user-patch re-apply — converges to the persisted setting. A toggle restarts the webserver fiber only when the bind differs, using fiber.update(config, noSave): the no-save path keeps the composed tree out of cordis.yml, which would otherwise trigger an HMR subtree reload.
Client src/client/ Registers the General-settings row (settings.general.item, order 15) with a native checkbox switch, the LAN URLs (primary first, all live NIC addresses shown, copy button), zh/en copy, and restart-tolerant polling.

The route fence accepts loopback or the deployment's trusted authorities, read live from the connection row's resolved config — the same boundary the /api gateway uses. Cross-site requests are refused.

Showing the opening section of the README — the full document lives in the repository以上为 README 开头摘要,完整文档在仓库内 · View the full README on GitHub →在 GitHub 查看完整 README →

← 上一个 Prev dsh-models-radar 下一个 Next dsh-plugin-session-notes →