安装
npx -y @deepseek-ai/dsh plugin --profile web add github:maxesisnclaw/dsh-lan-gate此安装命令根据 GitHub 仓库地址生成,是未经验证的安装起点。
README
维护者编写的文档快照。
dsh-lan-gate
English | 中文
Password gate + CIDR allowlist + proxy-header deny for DeepSeek Harness web.
dsh web --host 0.0.0.0 is rejected by the CLI. This bundle sets webserver.host to 0.0.0.0 through the official composition layer, then requires a password before the UI or /api is reachable from the LAN.
Install
dsh plugin --profile web add dsh-lan-gate
Or from GitHub:
dsh plugin --profile web add github:maxesisnclaw/dsh-lan-gate
Then open http://127.0.0.1:3080/dsh-lan-full/login and set a password (loopback only). After that, LAN clients get the login page.
Settings → LAN access / LAN 访问 edits CIDRs, proxy-header policy, and the password. The settings section and login page follow dsh's official zh/en locale.
What it does
| Control | Default |
|---|---|
| Listen on all interfaces | yes (bundle patch) |
| Password | unset until you set it from loopback |
| Inbound IPv4 CIDRs | 10.0.0.0/8, 172.16.0.0/12, 192.168.0.0/16 |
Reject X-Forwarded-* / Forwarded / Via | yes |
| Loopback bypasses password | yes (recovery) |
Policy file: $DSH_HOME/lan-gate.json (mode 0600). The password is stored as a scrypt verifier, never as plaintext. Session tokens are random 32-byte values; only their SHA-256 is kept in memory.
Residual risk
This is not a TLS terminator. On plain HTTP a LAN observer can still sniff the password and cookie. Do not put this on the public internet. Do not sit it behind a reverse proxy that adds forwarding headers — those requests are rejected on purpose.
See SECURITY.md.
License
MIT
项目文件与信号
以下项目是目录快照中检测到的公开仓库信号。
仓库信息
- 开发语言
- JavaScript
- 许可证
- MIT
- 最后更新
- 2026年8月15日 11:41
谨慎安装
请检查源代码、权限、生命周期脚本、依赖与网络访问;不受信任的插件应先在隔离环境中测试。