taichuy/deepseek-harness-auth 预览 preview

taichuy/deepseek-harness-auth

DeepSeek Harness 认证插件

Project Overview项目介绍

This is a native authentication bundle built exclusively for DeepSeek Harness (DSH) Web profile. It does not require modifying any code in the main DSH repository, and adds a public authentication proxy that runs in the same process as DSH. The original Harness WebServer is bound to a random port on 127.0.0.1, and only requests that pass authentication — including HTTP requests, static assets, RPC, SSE, and WebSocket connections — are forwarded to the backend. Before any user account is initialized, the plugin follows a fail-closed security model, so no default accounts or pre-generated random passwords are created.

The plugin is designed for users who need to expose their DSH Web service to public networks. It implements multiple layered security features, including password storage encrypted with scrypt, automatic locking after repeated failed login attempts, single-use captchas, and HttpOnly session tokens. It also supports IP/CIDR whitelist management, and users can manage accounts, passwords, and whitelist rules both via the command line interface and the built-in web UI. After installation, you only need to initialize your account via the dsh CLI command before starting DSH Web and accessing the proxy address.

The plugin only supports DSH version 0.1.x and requires the DSH Web profile to function properly. It can be installed directly via npm or built from source code, and it is released under the open-source Apache-2.0 license. When installing, you can pin a specific version to avoid unexpected automatic upgrades, and upgrading or uninstalling the plugin will not delete your saved account credentials, password hashes, or existing whitelist configurations. It also provides many environment variable configuration options, letting users customize listening ports, security policies, and other core parameters.

这是专为 DeepSeek Harness(DSH)Web 配置文件开发的原生认证 Bundle 插件,无需修改 DSH 主仓库代码,就能在同一进程中启动公共认证代理,并将原 Harness WebServer 绑定到 127.0.0.1 的随机端口上,仅转发通过认证的 HTTP、静态资源、RPC、SSE、WebSocket 等请求到后端。插件在账号未初始化时遵循默认关闭的安全模型,不会生成默认账号或随机密码,密码需要用户手动设置。

该插件面向需要将 DSH Web 服务暴露到公网访问的用户,提供了完善的安全认证机制,包括 scrypt 加密存储密码、登录失败锁定、单次有效验证码、HttpOnly 会话令牌等能力,同时支持 IP/CIDR 白名单管理,可从 CLI 和 Web 端管理账号、密码和白名单规则。安装后只需通过 dsh 命令初始化账号,即可启动 DSH Web 并访问认证代理地址。

插件仅支持 DSH 0.1.x 版本,需配合 DSH Web profile 使用,可通过 npm 或源码安装,采用 Apache-2.0 开源协议。安装时支持指定版本避免意外升级,升级或卸载插件不会删除已保存的账号、密码哈希和白名单配置。它提供了丰富的环境变量配置项,可自定义监听端口、安全策略等参数。

Pre-install check安装前体检Compatibility · Security兼容性 · 安全性 1 note1 项提示
  • 25 stars - an early-stage project星标 25,属于早期项目
DSH walks through these 9 checksDSH 会逐条核对这 9 项

Compatibility兼容性

  • DSH, Node, OS and profile requirementsDSH 版本 / Node 版本 / 操作系统 / profile 是否满足要求
  • External dependencies and runtimes (Electron / Python / Docker, ...)外部依赖与运行时(Electron / Python / Docker 等)是否齐备
  • Conflicts with installed plugins: command names, skill / tool names, ports, duplicate MCP registration与已装插件是否冲突:命令名、skill / tool 重名、端口占用、重复 MCP 注册

Security安全性

  • Repo matches the facts registered here; archived or abandoned?仓库是否与页面登记一致,是否归档或长期停更
  • Safety of preinstall / install / postinstall and install.sh / setup.ps1preinstall / install / postinstall 与 install.sh、setup.ps1 是否安全
  • curl|bash, download-then-execute, obfuscation, unrelated domains → stop immediatelycurl|bash、下载即执行、混淆代码、无关域名 → 立刻停止
  • Typosquatting or unmaintained packages among the new dependencies新增依赖里有没有 typosquatting 或无人维护的包
  • Requested permissions vs. what the feature actually needs申请了哪些权限、是否超出功能所需(filesystem / network / shell / clipboard)
  • Any sudo / admin requirement, plus uninstall and rollback是否要求 sudo / 管理员权限,以及卸载与回滚方式

Anything uncertain must be marked unknown with a note on how to confirm it. This site's signal screen is a static snapshot, not a security audit.拿不准的必须标「未知」并说明要我怎么确认。本站的信号筛查是静态快照,不能替代安全审计。

Or use CLI install (for developers)或使用命令行安装(适合开发者)

CLI Install命令行安装

dsh plugin --profile web add deepseek-harness-auth@0.4.0

把 taichuy/deepseek-harness-auth 加入你的 DSH 配置(web profile)即可启用。

READMEREADME

deepseek-harness-auth

CI npm

DeepSeek Harness Web profile 的树外认证 Bundle。在不修改 Harness 主仓库的条件下,它将原 WebServer 固定到 127.0.0.1 随机端口,并在同一进程中启动唯一的公共认证代理;HTTP、SPA 静态文件、RPC、SSE 与 WebSocket upgrade 只有通过认证后才会转发到 Harness。

安全模型

Browser -> public Auth Proxy -> authenticated -> 127.0.0.1:<random> Harness WebServer
  • 未初始化账号时公共代理保持 fail-closed,不生成默认账号或随机密码。
  • 密码由本机拥有者手动设置;除了不能为空,不强制长度、复杂度或必须排除用户名。
  • 默认白名单为空,因此本机和远程地址都必须登录;可用 CLI 添加 IP 或 CIDR。
  • 认证 Bundle 固定使用 Harness 的应用内 browse 目录选择器,远程浏览器选择服务器工作区时不会在宿主桌面弹出 Zenity/KDialog。未安装本 Bundle 的 DSH profile 仍使用 Harness 原有的自动选择策略。
  • 密码使用 Node.js scrypt 保存,状态目录权限为 0700,状态文件为 0600。
  • 默认连续失败 6 次锁定 30 秒,同时按“IP + 用户名”和全局 IP 计数。
  • 支持关闭验证码、始终验证、失败后验证;验证码短期有效且只能使用一次。
  • 浏览器仅持有 HttpOnly、SameSite=Strict 的随机会话 token;账号、密码或白名单修改会撤销旧会话。
  • Web 客户端在侧边栏底部提供退出登录,在设置中提供“账号与安全”页面;账号会话和白名单放行的访问者都可以管理 IP/CIDR 白名单,修改密码仍必须先验证当前密码。
  • “账号与安全”页面可以把验证码设为关闭、登录失败后开启或每次登录开启;Web 保存的策略会持久化并覆盖 DSH_AUTH_CAPTCHA_MODE 默认值。
  • 登录页会读取同一浏览器最近一次已认证 Harness 页面保存的安全主题快照,复用 --dsw-* 配色和页面背景。新浏览器首次访问尚无快照时使用随系统明暗变化的 Harness 风格默认主题。
  • 公网浏览器明确确认过 Harness 的同一版“内测声明”后,客户端会按完整声明文案在同源 localStorage 中记住确认;刷新或重新登录不再重复打扰,声明文案变化时仍会重新展示。
  • 代理只接受 loopback Harness 上游,并把通过认证的上游 Host 与 Origin 改写为 loopback authority,使 Harness 的本机敏感 RPC 在认证后可用。
  • HTTP 与 HTTPS 都可以使用。插件不会强制 TLS;secureCookie 由部署者选择。

当前兼容基线为 DeepSeek Harness 0.1.x(@deepseek-ai/dsh-host-webserver >=0.1.0-rc.2)。旧 0.0.x WebServer 使用不同的服务名,不在支持范围内。

安装与启动

以下命令都假定已经安装并能运行 dsh。插件只安装到 DSH 的 web profile(默认位于 ~/.dsh/profiles/web),不是安装成系统全局 npm 包,也不会修改 DeepSeek Harness 主仓库。

方式一:从 npm 安装(推荐)

npm 包已经包含构建好的 JavaScript,普通用户直接执行:

dsh plugin --profile web add deepseek-harness-auth@latest

如果需要固定版本,避免以后意外升级:

dsh plugin --profile web add deepseek-harness-auth@0.4.0

安装完成后初始化账号并启动 Web 模式:

dsh plugin --profile web exec dsh-auth init
dsh web

init 会在终端中交互式询问账号、密码和确认密码,密码不会出现在命令行参数或 shell history 中。浏览器访问终端输出的认证代理地址;默认监听端口是 3080。

Showing the opening section of the README — the full document lives in the repository以上为 README 开头摘要,完整文档在仓库内 · View the full README on GitHub →在 GitHub 查看完整 README →

← 上一个 Prev dsh-launcher 下一个 Next dsh-web-review →