dsh-full-remote: An Authenticated Reverse Proxy Plugin for DeepSeek Harness
juanwang-buaa/dsh-full-remote
dsh-full-remote provides an authenticated reverse proxy gateway for DeepSeek Harness, enabling mobile QR access, per-device sessions, and Host/Origin rewrite for secure remote access.
dsh-full-remote is a remote access plugin for DeepSeek Harness that places an authenticated reverse proxy in front of the Harness Web server, enabling the Web UI to be used through a public tunnel or from a local network device while keeping privileged APIs like settings, credentials, and directory browsing available. It solves the problem that DeepSeek Harness only accepts loopback requests, causing privileged endpoints to return 403 when accessed via a generic tunnel. The plugin rewrites Host/Origin headers and provides its own access-control layer to replace the original trust check. Core capabilities include token/device-session authentication, header rewriting, HTTP/SSE/WebSocket forwarding, and an optional Cloudflare quick tunnel.
How to Install
dsh plugin --profile web add dsh-full-remote- Category
- Integrations & Connections
- Platform
- DSH Plugin
- Author
- juanwang-buaa
- Distribution
- Plugin
dsh-full-remote Key Features
dsh-full-remote Repo Summary
What Does It Do?
dsh-full-remote is a DSH plugin for DeepSeek Harness that places an authenticated reverse proxy in front of the Harness Web server, enabling the Web UI to be used through a public tunnel or from a local network device while keeping privileged APIs like settings, credentials, and directory browsing available. It solves the problem that DeepSeek Harness only accepts loopback requests, causing privileged endpoints to return 403 when accessed via a generic tunnel. The plugin rewrites Host/Origin headers and provides its own access-control layer to replace the original trust check. Core capabilities include token/device-session authentication, header rewriting, HTTP/SSE/WebSocket forwarding, and an optional Cloudflare quick tunnel.
Core Features
- Authenticated reverse proxy: requests are accepted only with an access token, a one-time invite, or a valid device session; unauthenticated requests never reach the backend.
- Host/Origin rewrite: rewrites headers to loopback so privileged APIs pass Harness's trust check.
- Multi-protocol forwarding: supports HTTP, SSE, and WebSocket; compressible HTTP responses (HTML/JS/CSS/JSON/SVG, ≥1 KB) may be gzipped, while SSE and WebSocket are not.
- Settings panel: start/stop the proxy, change listen address, rotate token, and manage device sessions under Settings → Reverse proxy.
- Optional Cloudflare quick tunnel: generates a one-time QR invite that never contains the standing access token.
- Tunnel compatibility: works with SSH, frp, ngrok, Tailscale, cloudflared, or any managed tunnel pointing at the local endpoint.
How to Use This Plugin?
After enabling the plugin in DSH, go to Settings → Reverse proxy, press Start proxy to launch the local proxy, then press Start Cloudflare quick tunnel to generate a QR code and scan it with your phone. For a controlled network, point an existing SSH, frp, ngrok, Tailscale, or cloudflared tunnel at the proxy target shown in the panel. To adjust behavior, change the listen address, rotate the token, or manage device sessions in the settings panel.
This page is an independent rewrite of the plugin's official README — for authoritative documentation and the latest changes, refer to the source: juanwang-buaa/dsh-full-remote. The plugin is third-party code that runs on your machine once installed; inclusion does not imply endorsement — please review the source before installing.
