dsh-lan-gate
DeepSeek Harness 局域网密码门禁:密码 + CIDR 白名单 + 代理头拒绝
maxesisnclaw
@maxesisnclaw
⬇ 1
★ 0
main
安装
dsh plugin --profile web add github:maxesisnclaw/dsh-lan-gate
需要可复现安装时,可在仓库后追加 #commit 固定提交。
DeepSeek Harness 局域网密码门禁:密码 + CIDR 白名单 + 代理头拒绝
该插件未提供要点说明,请参考仓库 README。
access-controlai-agentauthenticationchinesecidrdeepseek
- 安装并启动 DeepSeek Harness:
npx @deepseek-ai/dsh web - 在终端执行上面的安装命令(CLI 会解析插件并核验来源)
- 用 dsh plugins list 确认已安装,必要时重启 Harness 生效
插件以当前 dsh 进程的权限运行,安装时可能执行代码。请先通读仓库源码与许可证,确认无破坏性命令与越权访问;本站只做索引,不对第三方插件安全性作担保。
| 代码仓库 | github.com/maxesisnclaw/dsh-lan-gate |
| 许可证 | MIT |
| 主要语言 | main |
| 下载量 | 1 |
| GitHub 星标 | 0 |
| 最近推送 | 2026-08-15 |
| 收录日期 | 2026-09-19 |
| 分类 | 安全与权限 |
事实信息来自公开插件目录快照(2026-10-01),介绍文案由本站再加工。
以下为插件仓库 README 全文(原始内容,由公开目录抓取整理)。
# dsh-lan-gate English | [中文](README.zh.md) Password gate + CIDR allowlist + proxy-header deny for [DeepSeek Harness](https://github.com/deepseek-ai/deepseek-harness) web. `dsh web --host 0.0.0.0` is rejected by the CLI. This bundle sets `webserver.host` to `0.0.0.0` through the official composition layer, then requires a password before the UI or `/api` is reachable from the LAN. ## Install ```sh dsh plugin --profile web add dsh-lan-gate ``` Or from GitHub: ```sh dsh plugin --profile web add github:maxesisnclaw/dsh-lan-gate ``` Then open `http://127.0.0.1:3080/dsh-lan-full/login` and set a password (loopback only). After that, LAN clients get the login page. Settings → **LAN access** / **LAN 访问** edits CIDRs, proxy-header policy, and the password. The settings section and login page follow dsh's official `zh`/`en` locale. ## What it does | Control | Default | |---|---| | Listen on all interfaces | yes (bundle patch) | | Password | unset until you set it from loopback | | Inbound IPv4 CIDRs | `10.0.0.0/8`, `172.16.0.0/12`, `192.168.0.0/16` | | Reject `X-Forwarded-*` / `Forwarded` / `Via` | yes | | Loopback bypasses password | yes (recovery) | Policy file: `$DSH_HOME/lan-gate.json` (mode `0600`). The password is stored as a scrypt verifier, never as plaintext. Session tokens are random 32-byte values; only their SHA-256 is kept in memory. ## Residual risk This is not a TLS terminator. On plain HTTP a LAN observer can still sniff the password and cookie. Do not put this on the public internet. Do not sit it behind a reverse proxy that adds forwarding headers — those requests are rejected on purpose. See [SECURITY.md](SECURITY.md). ## License MIT
数据来源:公开的 DeepSeek Harness 插件目录与各插件 GitHub 仓库。本站为独立第三方目录,与 DeepSeek、幻方(High-Flyer)及插件作者均无隶属或背书关系。