yauntyour/DSH-Encrypt 预览 preview

yauntyour/DSH-Encrypt

Plugin插件 Native原生 ⭐ 6 MIT Approval & Security审批与安全

| 项目 | 值 | | :--------- | :---------------------------------------------------------------------------------------------------------- | | 形态 | bundle(dsh.bundle.patch → cordis.patch.yml,随 profile 启动) |

catalog descriptioncatalog 简介 / catalog description:DeepSeek Harness 凭据加密插件,通过设置密码使用AES-256-GCM+SHA3-256实现的全流程加密+校验,运行时临时解密,内存安全。

Project Overview项目介绍

This is a DSH-native encryption plugin for user credentials that runs as a bundle in the DSH runtime. It stores all credentials in a single file at $DSH_HOME/.credentials.yaml, which remains plaintext if no password is set, and becomes AES-256-GCM encrypted after a password is configured. It replaces the default DSH credential provider with a drop-in integration that does not require any changes to existing DSH components like LLM adapters or web search tools. It also adds an "Encryption Security" settings panel to the DSH web user interface for easy password management. It uses Argon2id for secure key derivation and SHA3-256 for integrity checking.

Key security features include brute-force protection that locks out login attempts after multiple failures, output redaction to prevent credential leaks in server logs, integrity self-checking for plugin installation files, configurable stay-signed-in durations, and on-demand decryption that never caches plaintext credentials. The plugin also implements atomic writes and file locking to prevent credential file corruption. It will automatically check your DSH version when loaded, and throw a clear UNSUPPORTED_DSH error if it detects an incompatible major DSH version instead of failing silently. For remote deployments over LAN or tunnels, you can configure a list of trusted hosts to prevent unauthorized access.

To install the plugin, you first need to clone the repository, run pnpm install and pnpm pack to build the package, then add the generated tarball to your DSH profile via the dsh plugin add command. The plugin requires Node.js 24 or newer and is compatible with DSH version 0.1.0-rc.7 and newer. It is released under the permissive MIT open source license. When uninstalling, you must back up your credentials first because once the file is encrypted, it remains encrypted permanently and cannot be converted back to plaintext by the default DSH credential provider. Developers can also install directly from source for testing and custom modifications.

这是一款DSH原生的凭证加密插件,以bundle形态工作,将凭证存储在单个文件$DSH_HOME/.credentials.yaml中:未设置密码时为和官方一致的明文YAML,设置密码后原地替换为AES-256-GCM加密密文。它使用Argon2id派生密钥、SHA3-256做完整性校验,替换DSH默认凭证提供器,属于零修改的替换式集成,还为DSH网页端添加加密安全设置面板。

核心特性包括单文件双形态原地转换、防暴力解锁的失败计数锁定、凭证泄露输出脱敏、安装文件完整性自校验、免密登录有效期设置、阅后即焚即解密即用不缓存、热重载与原子写加文件锁,同时会在加载时检测DSH版本,跨大版本会明确报错不静默失效。

安装需要先打包,通过DSH插件命令添加到profile,依赖Node.js 24以上,兼容DSH 0.1.0-rc.7及以上版本,采用MIT许可证开源。卸载需要提前备份凭证文件,删除插件相关配置后移除,设密后凭证文件永久为密文,无法回退到明文状态,开发者可以从源码安装进行测试和调试。

Pre-install check安装前体检Compatibility · Security兼容性 · 安全性 1 warning1 项注意
  • Only 6 stars - very few users, little community feedback星标只有 6,几乎没人在用,遇到问题缺少社区反馈
DSH walks through these 9 checksDSH 会逐条核对这 9 项

Compatibility兼容性

  • DSH, Node, OS and profile requirementsDSH 版本 / Node 版本 / 操作系统 / profile 是否满足要求
  • External dependencies and runtimes (Electron / Python / Docker, ...)外部依赖与运行时(Electron / Python / Docker 等)是否齐备
  • Conflicts with installed plugins: command names, skill / tool names, ports, duplicate MCP registration与已装插件是否冲突:命令名、skill / tool 重名、端口占用、重复 MCP 注册

Security安全性

  • Repo matches the facts registered here; archived or abandoned?仓库是否与页面登记一致,是否归档或长期停更
  • Safety of preinstall / install / postinstall and install.sh / setup.ps1preinstall / install / postinstall 与 install.sh、setup.ps1 是否安全
  • curl|bash, download-then-execute, obfuscation, unrelated domains → stop immediatelycurl|bash、下载即执行、混淆代码、无关域名 → 立刻停止
  • Typosquatting or unmaintained packages among the new dependencies新增依赖里有没有 typosquatting 或无人维护的包
  • Requested permissions vs. what the feature actually needs申请了哪些权限、是否超出功能所需(filesystem / network / shell / clipboard)
  • Any sudo / admin requirement, plus uninstall and rollback是否要求 sudo / 管理员权限,以及卸载与回滚方式

Anything uncertain must be marked unknown with a note on how to confirm it. This site's signal screen is a static snapshot, not a security audit.拿不准的必须标「未知」并说明要我怎么确认。本站的信号筛查是静态快照,不能替代安全审计。

Or use CLI install (for developers)或使用命令行安装(适合开发者)

CLI Install命令行安装

dsh plugin --profile web add github:yauntyour/DSH-Encrypt

把 yauntyour/DSH-Encrypt 加入你的 DSH 配置(web profile)即可启用。

READMEREADME

dsh-encrypt

DSH 凭证加密插件(bundle 形态):一个文件($DSH_HOME/.credentials.yaml)双形态存储——未设密码时是与官方 dsh-credentials-local 完全一致的明文 YAML;设置密码后,同一文件原地替换为 AES-256-GCM 密文文档(Argon2id 派生密钥 + SHA3-256 完整性指纹)。浏览器只提交密码的 SHA3-256 摘要(前后端分离),模型请求按需临时解密、明文从不缓存;内置解锁爆破锁定、凭证泄露检测与输出脱敏、发行代码完整性自校验,并与 dsh 运行时三层解耦(详见部署架构)。

项目 值
形态 bundle(dsh.bundle.patch → cordis.patch.yml,随 profile 启动)
版本 0.1.0-rc.12
兼容运行时 dsh 0.1.0-rc.7 线(实测组合;跨线明确报 UNSUPPORTED_DSH)
依赖线 接缝包精确钉版(cordis 4.0.1、dsh-credentials 等 0.1.0-rc.6);独立包范围版(@node-rs/argon2/chokidar/yaml)
环境 Node.js ≥ 24;DSH @deepseek-ai/dsh@0.0.1-rc.1+
License MIT

特性

  • 单文件双形态:明文 YAML ↔ 密文 JSON 原地互转,不产生第二个文件、不迁移路径
  • AES-256-GCM:每条凭证独立随机 nonce,引用名绑定为 GCM AAD(换位即认证失败)
  • SHA3-256 损坏检测:条目级指纹 + 覆盖文档头部的文档级指纹,损坏文件启动即被拒绝(绝不当作“空库”);密文真实性由 AES-GCM 标签提供
  • Argon2id 密码派生(m=64 MiB, t=3, p=1,OWASP 对齐):密码不落盘,仅存盐与 AEAD 验证器;旧版 scrypt(v2)密文仍可解锁并在解锁时自动升级
  • 摘要校验(前后端分离):WebUI 用纯 JS Keccak-f[1600] 计算密码的 SHA3-256,只 POST { digest } 到后端;原始密码不离开浏览器
  • 解锁爆破锁定:连续失败计数持久化(重启不清零),达阈值(默认 5 次)指数退避(30s 起、×2、上限 15min),HTTP 429 + Retry-After
  • 凭证泄露检测与输出脱敏(Leak Guard):解析过的凭证值登记为掩码模式,WebUI 的 HTTP 响应体与 WebSocket 文本帧离开主机前替换为 [REDACTED:dsh-encrypt](分块边界安全的流式脱敏;rc.12 起真正接线)
  • 发行文件一致性自校验:构建时生成 lib/integrity-manifest.json(lib/ 全部构建文件与 cordis.patch.yml 的 SHA3-256),启动逐文件校验,并拒绝清单遗漏、越界文件名和内容不一致;该清单用于发现安装损坏,不作为防恶意改包的信任根
  • 免密登录滑块:0 = 每次输密码 / 1–30 天 / 永远;解锁成功后签发 256 位票据,默认仅 HttpOnly Cookie(响应体不回传);页面加载、标签页重新可见/聚焦时自动重试解锁,服务重启后切回页面即可
  • 仅本机密码操作:解锁、设密、改密和免密设置都要求 Host 回环 且 socket 回环;带代理转发头的请求不会被当成本机请求
  • 永远密文(ciphertext-only):设密后文件永不回退明文;外部明文替换在解锁态被立即重加密、锁定/启动态被拒绝(plaintextForbidden)
  • 阅后即焚:密文只在被使用的时刻解密,中间 Buffer 立即清零,密钥在锁定/卸载时清零
  • 按请求解密:明文只存活于单次操作,不缓存、不进日志
  • 热重载 + 原子写 + 文件锁(POSIX 强制 0600)+ 自动化解锁(DSH_CREDENTIAL_PASSWORD)
  • 运行时兼容护栏:加载时探测运行中 dsh 版本,同 0.1.x 线不同 rc 打警告,跨线抛 UNSUPPORTED_DSH(fail-loud,替代静默失效)——这是与 dsh 解耦的最后一层保险

Showing the opening section of the README — the full document lives in the repository以上为 README 开头摘要,完整文档在仓库内 · View the full README on GitHub →在 GitHub 查看完整 README →

← 上一个 Prev dsh-acp-plugin 下一个 Next dsh-interview →