dsh-auth-gateway
Authentication gateway plugin for DeepSeek Harness Web offering password and TOTP 2FA access control.
Install
$ dsh plugin --profile web add dsh-auth-gatewayPlugin Overview & Capabilities
AI-assisted organization based on the public repository snapshot. The content must be grounded in source evidence and does not replace compatibility or security verification.
Key Capabilities
- Intercepts all unauthenticated HTTP requests (401/302) and WebSocket upgrade attempts
- Generates a one-time setup password with mandatory onboarding password initialization
- Supports TOTP two-factor authentication (Google Authenticator, Authy, etc.) with encrypted secret storage and backup recovery codes
- Applies multi-layered brute-force rate limiting and IP locking
- Persists structured JSONL authentication audit logs with automatic rotation
- Injects client authentication settings panel into DeepSeek Harness web interface
Useful For
- Securing DeepSeek Harness web instances exposed over local networks or remote reverse proxies
- Enforcing password and TOTP two-factor authentication on harness web interfaces
- Tracking access attempts and security events through structured audit logs
Who It Fits
- Developers self-hosting DeepSeek Harness on remote servers or local area networks
- System administrators requiring password and 2FA protection for harness web endpoints
Documented Limitations
- Requires modifying port topology as the gateway takes the external port and shifts internal webserver to loopback
- Sub-path deployments (basePath) must be configured via profile patches
- Does not replace model execution guardrails or provider-level trust fences
DSH Compatibility
Version-specific runtime evidence collected by DSH Plugin. A missing result means we have not tested that combination yet.
Security Signals
Objective signals discovered from package metadata and source inspection. These are not a guarantee that a plugin is safe.
package.json declares 0 runtime, 2 development, 1 peer, and 0 optional dependencies.
package.json declares DSH bundle metadata.
GitHub reports the repository license as MIT.
A root package.json was captured and can be inspected by the registry.
Public GitHub source metadata is available for this registry snapshot.
Source & Registry Notes
Public provenance, Registry classification, and the latest source check for this entry, kept separate from runtime verification.
- Source repository
- xbzbing/dsh-auth-gateway
- Registry source
- GitHub · dsh-plugin topic
- Registry classification
- Plugin
- Source checked
- b79026a · 2026-09-27
This project is independently indexed from public source information. DSH Plugin is not affiliated with DeepSeek or the plugin author. Always check the author repository before installation.
Repository Activity
- GitHub stars
- 12GitHub stars
- Forks
- 2
- Open issues
- 0
- Last commit
- 2026-09-26
- Last release
- 2026-09-23
Related DSH Plugins
Ranked by overlapping capabilities, use cases, plugin type, categories, and DSH profile.
Local-first AI agent runtime and DSH plugin bundle providing sandboxed sessions, MCP tools, audit logs, and session replay.
View plugin →Conversational data analysis agent for DSH that executes SQL, governs schema catalogs, and renders interactive reports.
View plugin →Import and resume chat histories from 18+ AI coding agents into DeepSeek Harness with reverse export and sync.
View plugin →Multi-engine search provider for DeepSeek Harness with keyless fallback, time filtering, and UI configuration.
View plugin →