安全与权限
#dsh-plugin
dsh-jumpserver
通过对话查询与管理 JumpServer:资产、用户、账号、授权、会话、命令审计、命令过滤与 RBAC 角色,使用 AccessKeyID/AccessKeySecret(HTTP 签名)鉴权。
we39
@we39
⬇ 1
★ 0
main
安装
dsh plugin --profile web add github:we39/dsh-jumpserver
需要可复现安装时,可在仓库后追加 #commit 固定提交。
通过对话查询与管理 JumpServer:资产、用户、账号、授权、会话、命令审计、命令过滤与 RBAC 角色,使用 AccessKeyID/AccessKeySecret(HTTP 签名)鉴权。
该插件未提供要点说明,请参考仓库 README。
dsh-plugin
- 安装并启动 DeepSeek Harness:
npx @deepseek-ai/dsh web - 在终端执行上面的安装命令(CLI 会解析插件并核验来源)
- 用 dsh plugins list 确认已安装,必要时重启 Harness 生效
插件以当前 dsh 进程的权限运行,安装时可能执行代码。请先通读仓库源码与许可证,确认无破坏性命令与越权访问;本站只做索引,不对第三方插件安全性作担保。
| 代码仓库 | github.com/we39/dsh-jumpserver |
| 许可证 | 未标注(见仓库) |
| 主要语言 | main |
| 下载量 | 1 |
| GitHub 星标 | 0 |
| 最近推送 | 2026-09-14 |
| 收录日期 | 2026-09-19 |
| 分类 | 安全与权限 |
事实信息来自公开插件目录快照(2026-10-01),介绍文案由本站再加工。
以下为插件仓库 README 全文(原始内容,由公开目录抓取整理)。
# dsh-jumpserver [简体中文](./README.zh-CN.md) A DeepSeek Harness plugin for querying and managing JumpServer assets through conversation, authenticated with a JumpServer AccessKeyID/AccessKeySecret pair (HTTP Signature). ## Why dsh-jumpserver - Inspect JumpServer assets, users, accounts, permissions, sessions, command audit logs, user groups, command filters, asset-tree nodes, and RBAC roles/bindings through conversation. - Manage assets, accounts, users, permissions, user groups, command groups, command filters, asset-tree nodes, and custom RBAC roles/bindings, plus password/MFA/SSH-key resets for users. - Every write operation triggers a mandatory native user-approval prompt — the model cannot bypass it. - Secrets, passwords, public keys, MFA secrets, and account passphrases are redacted from read responses before they reach the model. - Authenticate with JumpServer's native HTTP Signature scheme (`hmac-sha256`); the AccessKeySecret stays in the local DSH credential store. ## Requirements | Component | Supported baseline | | --- | --- | | Node.js | 20.11 or newer | | DeepSeek Harness | `0.1.2-rc.1` | | JumpServer | REST API `v1` (Access Key authentication) | ## Installation (for the agent) For local development, install from the local path: ```bash npm ci dsh plugin --profile add link:/absolute/path/to/dsh-jumpserver ``` Once published, install a released, immutable tag whenever possible: ```bash dsh plugin --profile add github:we39/dsh-jumpserver#v ``` Install the mutable development branch only for testing: ```bash dsh plugin --profile add github:we39/dsh-jumpserver ``` Restart the selected DSH profile after installation. On Windows, use an absolute `link:C:/path/to/dsh-jumpserver` path. ## Configuration In DSH Web, open **Settings → Plugins → JumpServer asset lookup**. Configure: - **JumpServer URL**: the absolute base URL, for example `https://jumpserver.example.com`. - **Access Key**: create one from the JumpServer web console under your personal API Key list. - **Secret Key**: paired with the Access Key above. The Access Key/Secret Key use DSH's privileged loopback credential RPC — write-only, the stored values are never read back or displayed. The URL is stored in the `jumpserver` settings namespace as a non-secret field, so it is read back in plaintext and shown in the card for verification. HTTP and HTTPS both work out of the box — internal deployments without TLS certificates can use an `http://` URL with no extra setup. To enforce HTTPS only, disable it in plugin configuration: ```yaml allowInsecureHttp: false ``` The credential reference names default to `JUMPSERVER_ACCESS_KEY_ID` / `JUMPSERVER_ACCESS_KEY_SECRET` and can be changed with `akRef` / `skRef` in the plugin configuration. ### JumpServer permissions Create the AccessKey under a JumpServer account that only has read access to the assets you want visible to the assistant. Avoid using a super-admin account's key for this integration. ## Tools 53 tools (12 read-only / 41 write) across 10 domains. All write tools require native user approval. | Domain | Tools | Scope | | --- | --- | --- | | Assets | 5 | assets, details, create/update/delete | | Users | 7 | users, details, create/update/delete, password/MFA/SSH-key reset | | Accounts | 5 | asset accounts, details, create/update/delete | | Permissions | 5 | asset-permission rules, details, create/update/delete | | Sessions & Audit | 2 | terminal sessions, command audit logs | | User Groups | 5 | groups, details, create/update/delete | | Command Groups | 5 | command-pattern groups, details, create/update/delete | | Command Filters | 5 | security filters, details, create/update/delete | | Asset Tree | 6 | nodes, details, create/update/delete, move | | RBAC | 8 | roles, bindings, create/update/delete | See **[docs/tools.md](docs/tools.md)** for the full per-tool reference (name, method, path, description). Session termination and ticket approval are intentionally out of scope. ## Security and data boundaries - The AccessKeySecret never enters tool arguments, model messages, logs, or Git. - Account secrets/passphrases and user passwords/public keys/MFA secrets are explicitly excluded from every **read** tool's output, field by field. - Authenticated requests reject HTTP redirects to avoid forwarding signed requests to another origin. - Non-loopback HTTP is disabled by default (see `allowInsecureHttp`). - Requests have cooperative cancellation, timeouts, and bounded response sizes. - Error responses expose only a bounded status/detail description. - `id` parameters are validated as JumpServer UUIDs before being placed in a request path, preventing path injection. - All returned fields (names, addresses, comments, usernames, etc.) are treated as untrusted data, not model instructions. ## Development ```bash npm ci npm run verify ``` Tests use Node's built-in test runner and mocked JumpServer responses. ## Structure - `index.js` — generic execution engine + full endpoint catalog + write-approval gateway - `client.js` — settings-page form card (slot key `jumpserver`) - `cordis.patch.yml` — bundle patch (insert id `jumpserver` / name `dsh-jumpserver`) - `docs/tools.md` — full tool reference - `test/index.test.js` — `node:test` unit tests ## License MIT
数据来源:公开的 DeepSeek Harness 插件目录与各插件 GitHub 仓库。本站为独立第三方目录,与 DeepSeek、幻方(High-Flyer)及插件作者均无隶属或背书关系。