WebUI authentication
Yuuz12/dsh-webui-auth · themes
WebUI identity authentication: HTTP/transport layer forced login (resource, plug-in bundle, /api, WebSocket four-layer protection), server session + HttpOnly Cookie.
★ 8GitHub stars
0Forks
2026-08-15Last updated
JavaScriptLanguage
MITLicense
Key features
- First time enabledAuthentication is automatically turned off when credentials are not configured (all requests are allowed).
- The password is hashed with scrypt (Node's built-in memory hard KDF, resistant to GPU/ASIC blasting, zero dependency) in the dsh-webui-auth.json of the data directory (see the previous section for location), and the plain text is not written to disk.
- Automatic retry does not take effect on the current process (the core module has been loaded) and needs to be restarted again
- Or directly access /dsh-webui-auth/login, the page will display the "Create Administrator Account" form.
- The authentication takes effect immediately after creation, and the current browser automatically obtains a session.
Install command
dsh plugin --profile web add github:Yuuz12/dsh-webui-auth