Dsh Auth Gate
TecFancy/dsh-auth-gate · productivity
Login gate for the DeepSeek Harness (dsh) web surface: password or shared-token authentication, session cookies, rate limiting, and a user-management CLI.
★ 10GitHub stars
1Forks
2026-09-07Last updated
TypeScriptLanguage
MITLicense
Key features
- Every page, API call, and WebSocket connection is checked.
- Reverse-proxy deployment guide — Caddy/nginx setups, the browser-trust fence gotcha (Settings-page 403s behind a proxy, and why auth alone doesn't fix them), and the recommended semi-shell topology.
- Zero-dependency Node bin (dsh-auth-proxy): strictly bound to 127.0.0.1, stateless pass-through for pages/API, events.mux/events.host WebSocket tunneling, and a Set-Cookie Secure-attribute adaption (Safari fallback).
- Visitors without a valid session are sent to a simple login page (or rejected with 401 for API/script requests).
- Two ways to sign in (pick one in the configuration)
Requirements
- The dsh web profile running (dsh --profile web).
- If cookieSecure is true, your site must be served over https (browsers refuse secure cookies on plain http).
Install command
dsh plugin --profile web add github:TecFancy/dsh-auth-gate