rice-awa/dsh-lan-gateway
将DeepSeek Harness的Web GUI安全地开放到局域网或公网,自带密码鉴权,支持TLS。
Project Overview项目介绍
dsh-lan-gateway is a native DSH plugin that enables users to securely expose their DeepSeek Harness Web GUI to local area networks and the public internet. Since the native dsh web command blocks binding to 0.0.0.0 to avoid exposing remote code execution to untrusted networks, this plugin works around this restriction by running a separate reverse proxy that listens on all interfaces, while leaving DSH bound only to 127.0.0.1 to preserve baseline security. It is distributed as a pre-built package on npm, and can be installed directly via the DSH CLI command dsh plugin --profile web add @riceawa/dsh-lan-gateway without extra build permissions.
This plugin is designed for DSH users that need to access their Web GUI from outside the local machine, whether on a LAN or over the public internet. It follows a default-deny security model: all requests from any network require authentication via an HMAC session cookie obtained at the gateway login page, and LAN passwordless access is disabled by default and must be explicitly enabled in the settings. The plugin ships with an agent-accessible lan_gateway tool that lets users configure the gateway via natural language commands directly in DSH chat, no manual CLI input required.
dsh-lan-gateway requires DSH version 0.1.2-rc.1 or newer, is built with Node.js, and is released under the permissive MIT open source license. It blocks unencrypted plaintext HTTP listening by default, so users must configure one of three allowed setups to start the gateway: enable TLS with auto-generated self-signed certificates, use a custom signed TLS certificate pair, or route traffic through a trusted reverse proxy that terminates TLS. Self-signed certificates will trigger a browser security warning on first access, which is an expected behavior that users need to manually bypass to proceed.
dsh-lan-gateway 是专为 DeepSeek Harness (DSH) 开发的原生局域网/公网网关插件,解决了 DSH 原生 dsh web 命令拒绝绑定 0.0.0.0 端口,无法将 Web GUI 安全开放到外部网络的问题。它采用反向代理架构,让 DSH 继续绑定本地回环端口,另起网关服务监听公网/局域网请求,保留 DSH 原有的访问控制逻辑,同时额外增加网关层安全验证。插件已发布到 npm,支持通过 DSH 内置插件命令一键安装。
该插件面向需要在外网或局域网访问 DSH Web 界面的用户,默认拒绝所有未授权访问,所有外部来源访问都需要通过网关登录页获取 HMAC 会话 cookie,局域网免密访问需要手动开启配置,默认处于关闭状态。用户可以直接在 DSH 对话中通过自然语言指令调用插件提供的 lan_gateway 工具完成配置,无需手动输入命令,密码不会写入配置文件也不回显。
该插件基于 Node.js 开发,要求 DSH 版本不低于 0.1.2-rc.1,采用 MIT 许可开源,可免费使用与修改。它默认拒绝明文 HTTP 监听,用户需要选择启用 TLS 自签名证书、自定义证书或是受信任的反向代理终止 TLS 三种方式之一才能启动,若强制开启明文则需要用户自行承担安全风险。浏览器访问自签名证书会提示安全警告,属于预期行为。
请帮我安装这个 DSH 插件。安装前先完成【兼容性检查 + 安全性检查】,检查通过再动手。
插件:dsh-lan-gateway(rice-awa/dsh-lan-gateway)
仓库:https://github.com/rice-awa/dsh-lan-gateway
本站详情页:https://www.yhbd.top/plugins/rice-awa-dsh-lan-gateway/
本站登记:类型 plugin · 归类 原生 DSH 插件 · 许可证 MIT · ⭐ 6 · 最近提交 2026-10-02 · 主语言 TypeScript
按下面顺序执行,每步先把结论告诉我,再进入下一步:
【1 兼容性检查】
① 我这边:DSH 版本、Node 版本、操作系统、当前 profile(web / desktop)。
② 读它的 README、package.json、插件 manifest,列出它要求的 DSH 版本 / Node 版本 / 操作系统 / 外部依赖 / 需要另外先装的运行时。
③ 逐条比对,结论只写「满足 / 不满足 / 未知」三种;不满足的给出可行替代方案。
④ 检查是否和我已装的插件冲突:命令名重复、skill / tool 重名、端口占用、重复注册的 MCP server。
【2 安全性检查】
① 仓库可信度:和上面「本站登记」是否一致;star / fork 数、创建时间、最近提交,是否归档或长期停更。
② 安装脚本:逐行看 package.json 的 preinstall / install / postinstall,以及 install.sh、setup.ps1 之类脚本。出现 curl|bash、下载后直接执行、混淆代码、访问与插件功能无关的域名,立刻停下来告诉我,不要继续装。
③ 依赖:列出新增依赖,标出无人维护、或与知名包拼写近似的可疑包(typosquatting)。
④ 权限与副作用:它会读写哪些目录、访问哪些域名、需要哪些 DSH 权限(filesystem / network / shell / clipboard 等),以及怎么卸载和回滚。
⑤ 如果它要求 sudo / 管理员权限,或权限明显超出功能所需,先停下来问我。
【3 安装】
上面两步没有「不满足」和「高危项」时才执行;用官方推荐方式安装,不要自行提权。
【4 汇报】
用表格输出:检查项 / 结论 / 依据 / 是否需要我决策。拿不准的一律写「未知」并说明要我怎么确认——不要猜,也不要替我决定。
Send this message to DSH in your current session: it verifies compatibility and security first (answering met / not met / unknown item by item) and only installs once everything checks out — it will stop and ask you if it finds a high-risk item. The box scrolls; the copy is the full prompt. CLI install commands may not be accurate across systems, so DSH is the safer route.把上面这条消息直接发给当前会话里的 DSH:它会先核对兼容性与安全性(逐条给「满足 / 不满足 / 未知」),确认没问题再安装,有高危项会停下来问你。框内可滚动,复制到的是完整提示词;安装命令不一定准确,发给 DSH 更稳。
- Only 6 stars - very few users, little community feedback星标只有 6,几乎没人在用,遇到问题缺少社区反馈
DSH walks through these 9 checksDSH 会逐条核对这 9 项
Compatibility兼容性
- DSH, Node, OS and profile requirementsDSH 版本 / Node 版本 / 操作系统 / profile 是否满足要求
- External dependencies and runtimes (Electron / Python / Docker, ...)外部依赖与运行时(Electron / Python / Docker 等)是否齐备
- Conflicts with installed plugins: command names, skill / tool names, ports, duplicate MCP registration与已装插件是否冲突:命令名、skill / tool 重名、端口占用、重复 MCP 注册
Security安全性
- Repo matches the facts registered here; archived or abandoned?仓库是否与页面登记一致,是否归档或长期停更
- Safety of preinstall / install / postinstall and install.sh / setup.ps1preinstall / install / postinstall 与 install.sh、setup.ps1 是否安全
- curl|bash, download-then-execute, obfuscation, unrelated domains → stop immediatelycurl|bash、下载即执行、混淆代码、无关域名 → 立刻停止
- Typosquatting or unmaintained packages among the new dependencies新增依赖里有没有 typosquatting 或无人维护的包
- Requested permissions vs. what the feature actually needs申请了哪些权限、是否超出功能所需(filesystem / network / shell / clipboard)
- Any sudo / admin requirement, plus uninstall and rollback是否要求 sudo / 管理员权限,以及卸载与回滚方式
Anything uncertain must be marked unknown with a note on how to confirm it. This site's signal screen is a static snapshot, not a security audit.拿不准的必须标「未知」并说明要我怎么确认。本站的信号筛查是静态快照,不能替代安全审计。
Or use CLI install (for developers)或使用命令行安装(适合开发者)
CLI Install命令行安装
dsh plugin --profile web add @riceawa/dsh-lan-gateway
把 rice-awa/dsh-lan-gateway 加入你的 DSH 配置(web profile)即可启用。
READMEREADME
dsh-lan-gateway — LAN / 公网网关插件
dsh web 明确拒绝 --host 0.0.0.0,以免把远程代码执行暴露到网络。本插件的做法是让 dsh 继续只绑 127.0.0.1,另起一个反向代理监听未指定地址(双栈,IPv4 与 IPv6 客户端都可接入),转发到 loopback 端口并改写 Host / Origin。
默认拒绝:loopback、LAN、公网三种来源都要先在网关登录页取得 HMAC 会话 cookie,LAN 免密需要显式打开 lanPasswordless,默认关闭。底座要求 dsh ≥ 0.1.7(本插件按该版本的 settings API 写入配置;含 QVD-2026-57410 的上游修复),网关在进程内中继一条共享上游会话,上游自身的授权仍然把关每个请求,网关只决定谁可以使用这条会话。
插件另外提供两项功能:
- 不安全源 UUID shim:网关以纯 HTTP 的局域网地址服务页面,浏览器视其为不安全源,不提供
crypto.randomUUID。client bundle 在页面加载早期补一个基于getRandomValues的实现,工作区才能正常打开。 - TLS:自动生成并持久化的自签名证书,或者挂载自行签发的 PEM。自签名证书首次访问会有浏览器警告,属预期行为。
安装
已发布到 npm,安装的是预构建产物,不需要 allowBuilds 授权。可将下面这段话交给你的 agent:
帮我安装 dsh 插件
@riceawa/dsh-lan-gateway,遵循https://github.com/rice-awa/dsh-lan-gateway/blob/main/INSTALL.md
也可以手动执行:
dsh plugin --profile web add @riceawa/dsh-lan-gateway
dsh plugin ... add 会把参数转发给 profile 目录里的 pnpm。npm 包自带 lib/,不会触发 ERR_PNPM_GIT_DEP_PREPARE_NOT_ALLOWED。如果仍然报错,把报错条目写进 ~/.dsh/profiles/web/pnpm-workspace.yaml 的 allowBuilds 后重试,完整步骤见 INSTALL.md。
从源码构建:
git clone https://github.com/rice-awa/dsh-lan-gateway.git
cd dsh-lan-gateway
pnpm install
pnpm build # host → lib/index.js
pnpm build:client # client → lib/client.js
pnpm test # 216 项
仓库里还有一个 lan-gateway 技能,安装后可直接在 dsh 对话里说「设置网关密码为 …」「开启远程访问」,agent 会调用 lan_gateway 工具完成,密码以参数传入,不写入配置,也不回显。改密码也可以不走模型:在本机打开 Plugins 页的「LAN 网关」卡片,直接填两次新密码覆盖(见下「登录密码」)。安装方式见 INSTALL.md。
Showing the opening section of the README — the full document lives in the repository以上为 README 开头摘要,完整文档在仓库内 · View the full README on GitHub →在 GitHub 查看完整 README →
Aisland-SJL/dsh-reminder
grunmin/dsh-acp-enhanced
kenryu42/cc-safety-net
toby-bridges/api-relay-audit
saya-ch/dsh-mobile
liguobao/ds-harness-remote