studyzy/dsh-web-remote-access
一个开箱即用的 DeepSeek Harness (dsh) 插件:解锁 dsh web 的远程访问能力(--host 0.0.0.0),并让对外暴露的 Web UI 始终处于访问令牌(web token)保护之下——页面、/api RPC、WebSocket 下行全部在门卫之后;回环访问则无需令牌,本地使用零打扰。
catalog descriptioncatalog 简介 / catalog description:让DSH能够支持远程访问Web的插件,可指定WebToken进行认证
Project Overview项目介绍
This is a native plugin built exclusively for DeepSeek Harness (DSH) that enables remote access to the DSH Web UI with token-based access control. It does not require any modifications to the core DSH source code, as all functionality is implemented via DSH’s bundle plugin system. To install the plugin, you can run the command dsh plugin --profile web add https://github.com/studyzy/dsh-web-remote-access.git directly from your terminal, and uninstalling it will restore DSH to its default behavior. It supports three token modes: fixed command-line token, environment variable token, and randomly generated token at startup, and loopback access does not require a token at all.
This plugin is designed for users who need to access their local DSH Web service from outside the local network without exposing an unauthenticated service to the public internet. After installation, you only need to specify the bind address as 0.0.0.0 when starting DSH to enable remote access. The plugin automatically validates tokens for all external requests, including web pages, API endpoints, and WebSocket connections. When you start the service, the terminal will print a direct clickable link with the correct token appended, so you do not need to manually construct the URL to access the remote service.
This plugin requires Node.js version 18 or higher to run, and it is released under the permissive MIT open source license, so you can use, modify, and distribute it freely. It is compatible with PWA installation and works well with reverse proxies like Nginx and Caddy. One known limitation is that it does not generate token-enabled loopback URLs for model prompts. To develop the plugin locally, you can clone the repository, install dependencies with pnpm, and run unit and end-to-end tests to verify your changes before installing it from source.
这是一个专为 DeepSeek Harness (DSH) 开发的原生插件,用于为 DSH 的 Web UI 开启远程访问能力并添加访问令牌认证。该插件无需修改 DSH 源码,完全通过 bundle 插件机制实现,卸载后即可恢复 DSH 的默认行为。它支持固定令牌、环境变量令牌和随机生成令牌三种方式,本地回环访问无需令牌,不影响本地日常使用体验。
如果你需要在外网访问本地运行的 DSH Web 服务,又不想让服务无认证暴露在公网,这个插件就能满足需求。安装后只需在启动 DSH 时指定绑定地址为 0.0.0.0 即可开启远程访问,插件会自动对所有外部请求做令牌校验,包括页面、API 接口和 WebSocket 连接全部受保护。启动后终端会打印带令牌的可直接访问链接,使用非常方便。
该插件基于 Node.js 18 及以上版本开发,采用 MIT 开源许可,可免费使用和修改。它兼容 PWA 安装,也支持和 Nginx、Caddy 等反向代理配合使用,已知限制是不会为模型提示生成带令牌的回环 URL。使用前需要先安装好 DSH 环境,通过 DSH 的插件命令即可快速完成安装,本地开发也支持源码安装。
请帮我安装这个 DSH 插件。安装前先完成【兼容性检查 + 安全性检查】,检查通过再动手。
插件:dsh-web-remote-access(studyzy/dsh-web-remote-access)
仓库:https://github.com/studyzy/dsh-web-remote-access
本站详情页:https://www.yhbd.top/plugins/studyzy-dsh-web-remote-access/
本站登记:类型 plugin · 归类 原生 DSH 插件 · 许可证 MIT · ⭐ 6 · 最近提交 2026-08-23 · 主语言 TypeScript
按下面顺序执行,每步先把结论告诉我,再进入下一步:
【1 兼容性检查】
① 我这边:DSH 版本、Node 版本、操作系统、当前 profile(web / desktop)。
② 读它的 README、package.json、插件 manifest,列出它要求的 DSH 版本 / Node 版本 / 操作系统 / 外部依赖 / 需要另外先装的运行时。
③ 逐条比对,结论只写「满足 / 不满足 / 未知」三种;不满足的给出可行替代方案。
④ 检查是否和我已装的插件冲突:命令名重复、skill / tool 重名、端口占用、重复注册的 MCP server。
【2 安全性检查】
① 仓库可信度:和上面「本站登记」是否一致;star / fork 数、创建时间、最近提交,是否归档或长期停更。
② 安装脚本:逐行看 package.json 的 preinstall / install / postinstall,以及 install.sh、setup.ps1 之类脚本。出现 curl|bash、下载后直接执行、混淆代码、访问与插件功能无关的域名,立刻停下来告诉我,不要继续装。
③ 依赖:列出新增依赖,标出无人维护、或与知名包拼写近似的可疑包(typosquatting)。
④ 权限与副作用:它会读写哪些目录、访问哪些域名、需要哪些 DSH 权限(filesystem / network / shell / clipboard 等),以及怎么卸载和回滚。
⑤ 如果它要求 sudo / 管理员权限,或权限明显超出功能所需,先停下来问我。
【3 安装】
上面两步没有「不满足」和「高危项」时才执行;用官方推荐方式安装,不要自行提权。
【4 汇报】
用表格输出:检查项 / 结论 / 依据 / 是否需要我决策。拿不准的一律写「未知」并说明要我怎么确认——不要猜,也不要替我决定。
Send this message to DSH in your current session: it verifies compatibility and security first (answering met / not met / unknown item by item) and only installs once everything checks out — it will stop and ask you if it finds a high-risk item. The box scrolls; the copy is the full prompt. CLI install commands may not be accurate across systems, so DSH is the safer route.把上面这条消息直接发给当前会话里的 DSH:它会先核对兼容性与安全性(逐条给「满足 / 不满足 / 未知」),确认没问题再安装,有高危项会停下来问你。框内可滚动,复制到的是完整提示词;安装命令不一定准确,发给 DSH 更稳。
- Only 6 stars - very few users, little community feedback星标只有 6,几乎没人在用,遇到问题缺少社区反馈
DSH walks through these 9 checksDSH 会逐条核对这 9 项
Compatibility兼容性
- DSH, Node, OS and profile requirementsDSH 版本 / Node 版本 / 操作系统 / profile 是否满足要求
- External dependencies and runtimes (Electron / Python / Docker, ...)外部依赖与运行时(Electron / Python / Docker 等)是否齐备
- Conflicts with installed plugins: command names, skill / tool names, ports, duplicate MCP registration与已装插件是否冲突:命令名、skill / tool 重名、端口占用、重复 MCP 注册
Security安全性
- Repo matches the facts registered here; archived or abandoned?仓库是否与页面登记一致,是否归档或长期停更
- Safety of preinstall / install / postinstall and install.sh / setup.ps1preinstall / install / postinstall 与 install.sh、setup.ps1 是否安全
- curl|bash, download-then-execute, obfuscation, unrelated domains → stop immediatelycurl|bash、下载即执行、混淆代码、无关域名 → 立刻停止
- Typosquatting or unmaintained packages among the new dependencies新增依赖里有没有 typosquatting 或无人维护的包
- Requested permissions vs. what the feature actually needs申请了哪些权限、是否超出功能所需(filesystem / network / shell / clipboard)
- Any sudo / admin requirement, plus uninstall and rollback是否要求 sudo / 管理员权限,以及卸载与回滚方式
Anything uncertain must be marked unknown with a note on how to confirm it. This site's signal screen is a static snapshot, not a security audit.拿不准的必须标「未知」并说明要我怎么确认。本站的信号筛查是静态快照,不能替代安全审计。
Or use CLI install (for developers)或使用命令行安装(适合开发者)
CLI Install命令行安装
dsh plugin --profile web add @studyzy/dsh-web-remote-access
把 studyzy/dsh-web-remote-access 加入你的 DSH 配置(web profile)即可启用。
READMEREADME
dsh-web-remote-access
让 DeepSeek Harness(dsh)Web UI 支持远程访问,并用访问令牌做访问控制
不改动 harness 源码,全部通过 bundle 插件实现
一个开箱即用的 DeepSeek Harness (dsh) 插件:解锁 dsh web 的远程访问能力(--host 0.0.0.0),并让对外暴露的 Web UI 始终处于访问令牌(web token)保护之下——页面、/api RPC、WebSocket 下行全部在门卫之后;回环访问则无需令牌,本地使用零打扰。
开源项目:github.com/studyzy/dsh-web-remote-access · MIT 协议
目录
特性
- 🔓 远程访问:
--host 0.0.0.0可用,且始终有令牌保护——对外暴露的服务绝不会无认证运行。 - 🛡️ 全表面门卫:所有请求(页面、
/apiRPC、WebSocket 下行)都经过 web token 门卫:- 首次打开
http://<host>:<port>/?web_token=<token>→ 服务器 302 跳转到干净路径,并下发会话 Cookie(dsh_web_token,HttpOnly,SameSite=Lax,浏览器关闭即失效)。 - 之后请求携带 Cookie 正常访问,直到浏览器关闭。
- 首次打开
- 🔑 令牌仅对远程绑定启用:
--host 0.0.0.0时,解析顺序--web_token→ 环境变量$DSH_WEB_TOKEN→ 启动时随机生成的令牌;回环绑定不启用门禁(令牌为空)。 - 🖨️ 一键直达:启动时打印可直接打开的 URL(含
?web_token=),绑定所有网卡时还会打印 LAN 地址。 - ⏱️ 常数时间比较:令牌校验使用
sha256+timingSafeEqual,不泄漏令牌长度与内容。 - 📱 PWA 兼容:
/manifest.webmanifest豁免令牌,安装检测不受影响。 - 🌐 配置平面远程可达:通过令牌认证的
/api请求以回环权威呈现给下游信任围栏,使settings.*、credentials.*、agentPreset.*、host.*、llm.discoverModels等特权方法可远程访问。 - 🧩 零源码改动:不改动 harness 源码,全部通过 bundle 插件(patch 层)实现;卸载插件即可完全还原默认行为。
安装
需要 dsh 环境。安装为 web profile 的插件:
Showing the opening section of the README — the full document lives in the repository以上为 README 开头摘要,完整文档在仓库内 · View the full README on GitHub →在 GitHub 查看完整 README →
xmanrui/dsh-im
tencent-connect/dsh-qqbot
flymysql/dsh-remote
whiteguo233/dsh-openbiliclaw
omdsh-dev/dsh-lark
hanshanyike/dsh-yolo
THEWOLFWALKER/dsh-notifier