taichuy/deepseek-harness-auth
DeepSeek Harness 认证插件
Project Overview项目介绍
This is a native authentication bundle built exclusively for DeepSeek Harness (DSH) Web profile. It does not require modifying any code in the main DSH repository, and adds a public authentication proxy that runs in the same process as DSH. The original Harness WebServer is bound to a random port on 127.0.0.1, and only requests that pass authentication — including HTTP requests, static assets, RPC, SSE, and WebSocket connections — are forwarded to the backend. Before any user account is initialized, the plugin follows a fail-closed security model, so no default accounts or pre-generated random passwords are created.
The plugin is designed for users who need to expose their DSH Web service to public networks. It implements multiple layered security features, including password storage encrypted with scrypt, automatic locking after repeated failed login attempts, single-use captchas, and HttpOnly session tokens. It also supports IP/CIDR whitelist management, and users can manage accounts, passwords, and whitelist rules both via the command line interface and the built-in web UI. After installation, you only need to initialize your account via the dsh CLI command before starting DSH Web and accessing the proxy address.
The plugin only supports DSH version 0.1.x and requires the DSH Web profile to function properly. It can be installed directly via npm or built from source code, and it is released under the open-source Apache-2.0 license. When installing, you can pin a specific version to avoid unexpected automatic upgrades, and upgrading or uninstalling the plugin will not delete your saved account credentials, password hashes, or existing whitelist configurations. It also provides many environment variable configuration options, letting users customize listening ports, security policies, and other core parameters.
这是专为 DeepSeek Harness(DSH)Web 配置文件开发的原生认证 Bundle 插件,无需修改 DSH 主仓库代码,就能在同一进程中启动公共认证代理,并将原 Harness WebServer 绑定到 127.0.0.1 的随机端口上,仅转发通过认证的 HTTP、静态资源、RPC、SSE、WebSocket 等请求到后端。插件在账号未初始化时遵循默认关闭的安全模型,不会生成默认账号或随机密码,密码需要用户手动设置。
该插件面向需要将 DSH Web 服务暴露到公网访问的用户,提供了完善的安全认证机制,包括 scrypt 加密存储密码、登录失败锁定、单次有效验证码、HttpOnly 会话令牌等能力,同时支持 IP/CIDR 白名单管理,可从 CLI 和 Web 端管理账号、密码和白名单规则。安装后只需通过 dsh 命令初始化账号,即可启动 DSH Web 并访问认证代理地址。
插件仅支持 DSH 0.1.x 版本,需配合 DSH Web profile 使用,可通过 npm 或源码安装,采用 Apache-2.0 开源协议。安装时支持指定版本避免意外升级,升级或卸载插件不会删除已保存的账号、密码哈希和白名单配置。它提供了丰富的环境变量配置项,可自定义监听端口、安全策略等参数。
请帮我安装这个 DSH 插件。安装前先完成【兼容性检查 + 安全性检查】,检查通过再动手。
插件:deepseek-harness-auth(taichuy/deepseek-harness-auth)
仓库:https://github.com/taichuy/deepseek-harness-auth
本站详情页:https://www.yhbd.top/plugins/taichuy-deepseek-harness-auth/
本站登记:类型 plugin · 归类 原生 DSH 插件 · 许可证 Apache-2.0 · ⭐ 25 · 最近提交 2026-10-02 · 主语言 TypeScript
按下面顺序执行,每步先把结论告诉我,再进入下一步:
【1 兼容性检查】
① 我这边:DSH 版本、Node 版本、操作系统、当前 profile(web / desktop)。
② 读它的 README、package.json、插件 manifest,列出它要求的 DSH 版本 / Node 版本 / 操作系统 / 外部依赖 / 需要另外先装的运行时。
③ 逐条比对,结论只写「满足 / 不满足 / 未知」三种;不满足的给出可行替代方案。
④ 检查是否和我已装的插件冲突:命令名重复、skill / tool 重名、端口占用、重复注册的 MCP server。
【2 安全性检查】
① 仓库可信度:和上面「本站登记」是否一致;star / fork 数、创建时间、最近提交,是否归档或长期停更。
② 安装脚本:逐行看 package.json 的 preinstall / install / postinstall,以及 install.sh、setup.ps1 之类脚本。出现 curl|bash、下载后直接执行、混淆代码、访问与插件功能无关的域名,立刻停下来告诉我,不要继续装。
③ 依赖:列出新增依赖,标出无人维护、或与知名包拼写近似的可疑包(typosquatting)。
④ 权限与副作用:它会读写哪些目录、访问哪些域名、需要哪些 DSH 权限(filesystem / network / shell / clipboard 等),以及怎么卸载和回滚。
⑤ 如果它要求 sudo / 管理员权限,或权限明显超出功能所需,先停下来问我。
【3 安装】
上面两步没有「不满足」和「高危项」时才执行;用官方推荐方式安装,不要自行提权。
【4 汇报】
用表格输出:检查项 / 结论 / 依据 / 是否需要我决策。拿不准的一律写「未知」并说明要我怎么确认——不要猜,也不要替我决定。
Send this message to DSH in your current session: it verifies compatibility and security first (answering met / not met / unknown item by item) and only installs once everything checks out — it will stop and ask you if it finds a high-risk item. The box scrolls; the copy is the full prompt. CLI install commands may not be accurate across systems, so DSH is the safer route.把上面这条消息直接发给当前会话里的 DSH:它会先核对兼容性与安全性(逐条给「满足 / 不满足 / 未知」),确认没问题再安装,有高危项会停下来问你。框内可滚动,复制到的是完整提示词;安装命令不一定准确,发给 DSH 更稳。
- 25 stars - an early-stage project星标 25,属于早期项目
DSH walks through these 9 checksDSH 会逐条核对这 9 项
Compatibility兼容性
- DSH, Node, OS and profile requirementsDSH 版本 / Node 版本 / 操作系统 / profile 是否满足要求
- External dependencies and runtimes (Electron / Python / Docker, ...)外部依赖与运行时(Electron / Python / Docker 等)是否齐备
- Conflicts with installed plugins: command names, skill / tool names, ports, duplicate MCP registration与已装插件是否冲突:命令名、skill / tool 重名、端口占用、重复 MCP 注册
Security安全性
- Repo matches the facts registered here; archived or abandoned?仓库是否与页面登记一致,是否归档或长期停更
- Safety of preinstall / install / postinstall and install.sh / setup.ps1preinstall / install / postinstall 与 install.sh、setup.ps1 是否安全
- curl|bash, download-then-execute, obfuscation, unrelated domains → stop immediatelycurl|bash、下载即执行、混淆代码、无关域名 → 立刻停止
- Typosquatting or unmaintained packages among the new dependencies新增依赖里有没有 typosquatting 或无人维护的包
- Requested permissions vs. what the feature actually needs申请了哪些权限、是否超出功能所需(filesystem / network / shell / clipboard)
- Any sudo / admin requirement, plus uninstall and rollback是否要求 sudo / 管理员权限,以及卸载与回滚方式
Anything uncertain must be marked unknown with a note on how to confirm it. This site's signal screen is a static snapshot, not a security audit.拿不准的必须标「未知」并说明要我怎么确认。本站的信号筛查是静态快照,不能替代安全审计。
Or use CLI install (for developers)或使用命令行安装(适合开发者)
CLI Install命令行安装
dsh plugin --profile web add deepseek-harness-auth@0.4.0
把 taichuy/deepseek-harness-auth 加入你的 DSH 配置(web profile)即可启用。
READMEREADME
deepseek-harness-auth
DeepSeek Harness Web profile 的树外认证 Bundle。在不修改 Harness 主仓库的条件下,它将原 WebServer 固定到 127.0.0.1 随机端口,并在同一进程中启动唯一的公共认证代理;HTTP、SPA 静态文件、RPC、SSE 与 WebSocket upgrade 只有通过认证后才会转发到 Harness。
安全模型
Browser -> public Auth Proxy -> authenticated -> 127.0.0.1:<random> Harness WebServer
- 未初始化账号时公共代理保持 fail-closed,不生成默认账号或随机密码。
- 密码由本机拥有者手动设置;除了不能为空,不强制长度、复杂度或必须排除用户名。
- 默认白名单为空,因此本机和远程地址都必须登录;可用 CLI 添加 IP 或 CIDR。
- 认证 Bundle 固定使用 Harness 的应用内
browse目录选择器,远程浏览器选择服务器工作区时不会在宿主桌面弹出 Zenity/KDialog。未安装本 Bundle 的 DSH profile 仍使用 Harness 原有的自动选择策略。 - 密码使用 Node.js
scrypt保存,状态目录权限为0700,状态文件为0600。 - 默认连续失败 6 次锁定 30 秒,同时按“IP + 用户名”和全局 IP 计数。
- 支持关闭验证码、始终验证、失败后验证;验证码短期有效且只能使用一次。
- 浏览器仅持有 HttpOnly、SameSite=Strict 的随机会话 token;账号、密码或白名单修改会撤销旧会话。
- Web 客户端在侧边栏底部提供退出登录,在设置中提供“账号与安全”页面;账号会话和白名单放行的访问者都可以管理 IP/CIDR 白名单,修改密码仍必须先验证当前密码。
- “账号与安全”页面可以把验证码设为关闭、登录失败后开启或每次登录开启;Web 保存的策略会持久化并覆盖
DSH_AUTH_CAPTCHA_MODE默认值。 - 登录页会读取同一浏览器最近一次已认证 Harness 页面保存的安全主题快照,复用
--dsw-*配色和页面背景。新浏览器首次访问尚无快照时使用随系统明暗变化的 Harness 风格默认主题。 - 公网浏览器明确确认过 Harness 的同一版“内测声明”后,客户端会按完整声明文案在同源
localStorage中记住确认;刷新或重新登录不再重复打扰,声明文案变化时仍会重新展示。 - 代理只接受 loopback Harness 上游,并把通过认证的上游 Host 与 Origin 改写为 loopback authority,使 Harness 的本机敏感 RPC 在认证后可用。
- HTTP 与 HTTPS 都可以使用。插件不会强制 TLS;
secureCookie由部署者选择。
当前兼容基线为 DeepSeek Harness 0.1.x(@deepseek-ai/dsh-host-webserver >=0.1.0-rc.2)。旧 0.0.x WebServer 使用不同的服务名,不在支持范围内。
安装与启动
以下命令都假定已经安装并能运行 dsh。插件只安装到 DSH 的 web profile(默认位于 ~/.dsh/profiles/web),不是安装成系统全局 npm 包,也不会修改 DeepSeek Harness 主仓库。
方式一:从 npm 安装(推荐)
npm 包已经包含构建好的 JavaScript,普通用户直接执行:
dsh plugin --profile web add deepseek-harness-auth@latest
如果需要固定版本,避免以后意外升级:
dsh plugin --profile web add deepseek-harness-auth@0.4.0
安装完成后初始化账号并启动 Web 模式:
dsh plugin --profile web exec dsh-auth init
dsh web
init 会在终端中交互式询问账号、密码和确认密码,密码不会出现在命令行参数或 shell history 中。浏览器访问终端输出的认证代理地址;默认监听端口是 3080。
Showing the opening section of the README — the full document lives in the repository以上为 README 开头摘要,完整文档在仓库内 · View the full README on GitHub →在 GitHub 查看完整 README →
kenryu42/cc-safety-net
hyhmrright/brooks-lint
zhu1090093659/dsh-trading
lire1131/dsh-undo-savepoint
jigjoy-ai/baro
c3ll256/dsh-toy
huaweicloud/huaweicloud-devkit