Dsh Web Auth
SummerSec/dsh-web-auth · skills
Transport-level authentication gate for the DeepSeek Harness Web GUI.
★ 2GitHub stars
0Forks
2026-08-20Last updated
JavaScriptLanguage
MITLicense
Key features
- CoverageHTTP routes and WebSocket / HTTP upgrade paths
- Binding to 0.0.0.0 or putting the port behind a reverse proxy can expose the full control surface.
- Counters are stored in process memory, so a restart clears them and multiple instances do not share state.
- Successful form login responds with 303 + Set-Cookie (dsh_web_auth) and Location set to a sanitized relative path (blocks //evil, absolute URLs, and header-injection characters).
- Default modealways — login required even on 127.0.0.1
Requirements
- DeepSeek Harness with a web profile (peer: @deepseek-ai/cordis ^4.0.1)
- A password hash in the process environment (recommended), or a temporary plaintext password
Install command
dsh plugin --profile web add github:SummerSec/dsh-web-auth