Skills Plugins MCP Prompt Model 导航 博客 资讯 我的中心

dsh-remote-access

Reach local DeepSeek Harness web from the LAN, Cloudflare Tunnel, or an SSH reverse forward.

nateyu @nateyu ⬇ 2 ★ 0 main

安装

dsh plugin --profile web add github:nateyu/dsh-remote-access
下载安装清单

需要可复现安装时,可在仓库后追加 #commit 固定提交。

Reach local DeepSeek Harness web from the LAN, Cloudflare Tunnel, or an SSH reverse forward.

该插件未提供要点说明,请参考仓库 README。

  1. 安装并启动 DeepSeek Harness:npx @deepseek-ai/dsh web
  2. 在终端执行上面的安装命令(CLI 会解析插件并核验来源)
  3. 用 dsh plugins list 确认已安装,必要时重启 Harness 生效

插件以当前 dsh 进程的权限运行,安装时可能执行代码。请先通读仓库源码与许可证,确认无破坏性命令与越权访问;本站只做索引,不对第三方插件安全性作担保。

代码仓库github.com/nateyu/dsh-remote-access
许可证MIT
主要语言main
下载量2
GitHub 星标0
最近推送2026-09-11
收录日期2026-09-19
分类工具与能力

事实信息来自公开插件目录快照(2026-10-01),介绍文案由本站再加工。

以下为插件仓库 README 全文(原始内容,由公开目录抓取整理)。

# @neil-yu/dsh-remote-access

English | [中文](README.zh.md)

A DeepSeek Harness settings plugin. After LAN, Cloudflare, or SSH is started, this machine listens on `listenPort` (default `3090`) and reverse-proxies HTTP and WebSocket onto loopback `dsh web`. The three entries share that port and it is not listened on while all are off. A remote entry is host-equivalent; public access requires the 10-character PIN.

`dsh web` itself stays bound to loopback. The 3090 hop talks to `dsh web` as `127.0.0.1:`, rewrites Host/Origin/Referer and loopback `Location` headers, and completes the launch-token cookie exchange so a phone never needs the URL printed by `dsh web`. On the index document it sets Connection's documented `__DSH_TRANSPORT__.ownsHost` flag so Host settings (models, plugin config) stay host-backed: the browser hostname is still the LAN or public name. This plugin's settings UI uses the public slots / locale / Connection RPC APIs.

The settings nav label follows the product locale: 「远程访问」 in Chinese, “Remote access” in English. LAN, Cloudflare, and SSH URLs each get a QR code on that page.

State is a single file, `$DSH_HOME/storages/dsh-remote-access.json` (mode `0600`). `dsh plugin remove` runs `preuninstall` and deletes that file, plus leftover `$DSH_HOME/dsh-gateway/` and `$DSH_HOME/storages/dsh-remote-proxyy.json` from earlier names. The `storages` directory is left in place.

## Install

```sh
dsh plugin --profile web add @neil-yu/dsh-remote-access
```

From a local checkout:

```sh
dsh plugin --profile web add /path/to/dsh-remote-access
```

Restart `dsh web`, then open Settings → Remote access.

Optional plugin config in the web profile:

```yaml
- id: dsh-remote-access
  name: '@neil-yu/dsh-remote-access'
  config:
    listenPort: 3090
    listenHost: 0.0.0.0
    cloudflaredPath: ''   # empty → PATH, then this package's bin/, then download
```

## Usage

### LAN

Turn on Start. Scan the QR code or open a listed `http://:3090` URL on another device on the same network. LAN PIN is off by default. The machine does not listen on that port while every entry is off.

### Cloudflare

`cloudflared` is **not** shipped in the npm tarball (20MB+ per OS). The first “Start public access” downloads the current GitHub release into **this package’s** `bin/` directory (`node_modules/@neil-yu/dsh-remote-access/bin/cloudflared`). That path is not under `$DSH_HOME`. An executable already on `PATH`, Homebrew’s usual bins, or `cloudflaredPath` is used instead and no download runs.

- Quick tunnel: Start public access. Cloudflare prints a `*.trycloudflare.com` URL (QR on the settings page). The public PIN is required.
- Named tunnel: paste a tunnel token from Zero Trust. Point that tunnel’s ingress at `http://127.0.0.1:3090` (or your `listenPort`).

### SSH reverse forward

Fill `user@vps`, the SSH login port (default 22; use 2222 or any sshd port), and the remote access port, plus a private key path or a password. Start forward. The plugin opens an SSH2 session from Node and reverse-forwards:

```text
VPS 0.0.0.0:  →  127.0.0.1:
```

Same as `ssh -R 0.0.0.0::127.0.0.1:`. Reaching that port from the public internet or LAN needs remote sshd `AllowTcpForwarding yes` and `GatewayPorts clientspecified` (or `yes`). With the default `GatewayPorts no` the port binds `127.0.0.1` only; the page shows that hint and drops the SSH session instead of marking it running. The plugin does not change remote sshd. OpenSSH does not have to be installed on this machine. LAN, Cloudflare, and SSH share that one local `listenPort` and can run together. Public PIN is required when the Host is not private.

## Security

A remote session is the same as sitting at this machine: the visitor can run the local agent **and** open Settings → Remote access (read PINs, start or stop LAN / Cloudflare / SSH). The shared `listenPort` hop rewrites Host/Origin to loopback and completes `dsh web`'s launch-token cookie exchange, so a phone never needs the URL printed by `dsh web`. Public Hosts always require the 10-character PIN. Starting Cloudflare or SSH asks for confirmation. Login guesses are rate-limited per client IP (`cf-connecting-ip` on Cloudflare, otherwise the TCP peer). Do not put this listener on an untrusted network without the PIN.

## Develop

```sh
npm install
npm test
```

`npm install` builds the browser bundle (`client/client.js`). After changing files under `client/`, run `npm run build:client` and refresh `dsh web`.

## Uninstall

```sh
dsh plugin --profile web remove @neil-yu/dsh-remote-access
```

Restart `dsh web`. The `preuninstall` script removes `$DSH_HOME/storages/dsh-remote-access.json`. Removing the npm package also deletes `bin/cloudflared`. If `DSH_HOME` is set only for `dsh web`, export the same value when removing the plugin.

## Limits

- Control RPCs use Connection's JSON envelope on a dedicated prefix mounted on this plugin's `webServer`. LAN, Cloudflare, and SSH all reverse-proxy through `listenPort`. That hop rewrites Host/Origin to loopback, completes the launch-token cookie exchange, and sets `ownsHost` on the index document.
- Named-tunnel DNS and ingress are configured in Cloudflare, not here.
- `dsh web` itself stays on loopback. Opening `0.0.0.0` on the Harness server is still unsupported.

数据来源:公开的 DeepSeek Harness 插件目录与各插件 GitHub 仓库。本站为独立第三方目录,与 DeepSeek、幻方(High-Flyer)及插件作者均无隶属或背书关系。

每日精选 Skill 推荐,免费送到你邮箱

输入邮箱,每天接收一个精选 AI Agent 技能推荐。完全免费,持续更新。

提交后我们会发送一封确认邮件,点击邮件里的链接才会开始收信。

完全免费,取消任意时间。我们不会发送垃圾邮件。