dsh-remote: A Remote Access Security Plugin for DeepSeek Harness
xgone/dsh-remote
Secure remote access for DeepSeek Harness: account/password auth, MFA (TOTP) gate, role-based access, and in-browser directory picker, enabling safe external exposure of dsh web.
dsh-remote is a remote access security plugin built for DeepSeek Harness, adding account/password authentication and MFA (TOTP) two-factor verification to the DSH web interface, enabling secure remote use of full features from external browsers. It solves the problem of DSH's privileged APIs being locked to loopback and the lack of an authentication layer for remote deployments. Core capabilities include a login gate, role-based permissions, MFA, remote directory selection, and multilingual/theme support.
How to Install
dsh plugin --profile web add @xgone/dsh-remote- Category
- Integrations & Connections
- Platform
- DSH Plugin
- Author
- xgone
- Distribution
- Plugin
dsh-remote Key Features
dsh-remote Repo Summary
What Does It Do?
dsh-remote is a DSH plugin for DeepSeek Harness that adds account/password authentication and MFA (TOTP) two-factor verification to the DSH web interface, enabling secure remote access from external browsers. It solves the problem of DSH's privileged APIs being locked to loopback and the lack of an authentication layer for remote deployments. The plugin also replaces the native directory picker with an in-browser dialog. Core capabilities include a login gate, role-based permissions, MFA, remote directory selection, and multilingual/theme support.
Core Features
- Complete login gate: unauthenticated access to any path redirects to a self-contained login page; /api and WebSocket require valid session cookies.
- Secure sessions and password storage: HMAC-SHA256 signed HttpOnly cookies, scrypt-hashed passwords, and rate limiting on failed logins (IP+username).
- MFA two-factor verification: compatible with standard authenticators like Google Authenticator, supports QR code binding, backup codes, and admin recovery.
- Role-based access: admin-only mode by default; can be disabled to enable admin/user/guest method-level permissions.
- Remote directory picker: replaces the native OS dialog with an in-browser two-pane directory browser with breadcrumbs and folder creation.
- Multilingual and theme following: UI supports Chinese and English, automatically follows DSH's language and light/dark theme settings.
How to Use This Plugin?
After enabling the plugin in DSH and restarting dsh web, the first visit enters a bootstrap mode where only the local machine can create the initial admin account. Once set up, external browsers accessing via a reverse proxy will see a login page requiring credentials and, if MFA is enabled, a time-based one-time code. After login, users can use all features including workspace selection and adding workspaces. When the session expires, a full-screen re-login overlay appears. Admins can manage accounts, reset passwords, and enable or disable MFA from the settings page.
This page is an independent rewrite of the plugin's official README — for authoritative documentation and the latest changes, refer to the source: xgone/dsh-remote. The plugin is third-party code that runs on your machine once installed; inclusion does not imply endorsement — please review the source before installing.
