← DeepSeek Harness Plugins
DeepSeek Harness PluginManifest Valid

dsh-trusted-proxy-auth

DeepSeek Harness plugin providing trusted reverse proxy authentication alongside native browser auth fallback.

Developer ToolsBrowser & WebSecurity & PolicyRemote Execution
0GitHub Stars0ForksUpdated2026-09-25

Install

$ dsh plugin --profile web add /path/to/dsh-trusted-proxy-auth

Plugin Overview & Capabilities

AI-assisted organization based on the public repository snapshot. The content must be grounded in source evidence and does not replace compatibility or security verification.

source-grounded
dsh-trusted-proxy-auth is a host-only DeepSeek Harness (DSH) plugin that enables a secondary authentication path for deployments fronted by reverse proxies such as Traefik and Keycloak OIDC. It validates private shared secret headers injected by the trusted proxy to authenticate callers while retaining DSH's native token and cookie flows for direct or SSH loopback access.

Key Capabilities

  • Validates private shared secret headers from upstream reverse proxies using timing-safe comparisons
  • Preserves native DeepSeek Harness browser token and cookie authentication as a fallback
  • Maintains Host and Origin fencing to prevent DNS rebinding and cross-site request attacks
  • Injects client-side transport ownsHost bootstrap to maintain host settings persistence across remote origins
  • Performs fail-closed startup validation to verify runtime auth semantics before booting

Useful For

  • Securing DeepSeek Harness behind Traefik, Keycloak OIDC, or similar enterprise reverse proxies
  • Allowing remote operator access via corporate single sign-on without breaking emergency local SSH access
  • Persisting Model catalog and Plugin configurations when accessing DSH from non-loopback domains

Who It Fits

  • DevOps engineers deploying DeepSeek Harness in containerized or Kubernetes environments
  • System administrators integrating DSH with corporate single sign-on (OIDC) identity providers
  • Security-focused operators seeking defence-in-depth auth boundaries

Documented Limitations

  • Requires an isolated network or TLS between the reverse proxy and DSH to prevent secret sniffing
  • Does not handle OIDC or JWT token parsing directly, relying on the upstream proxy to perform authentication
  • Fails loudly on startup if DSH_PROXY_AUTH_SECRET is absent, malformed, or shorter than 32 bytes

DSH Compatibility

Version-specific runtime evidence collected by DSH Plugin. A missing result means we have not tested that combination yet.

Not tested yetNo runtime compatibility tests have been published yet.

Security Signals

Objective signals discovered from package metadata and source inspection. These are not a guarantee that a plugin is safe.

Dependency Counts

package.json declares 0 runtime, 0 development, 0 peer, and 0 optional dependencies.

info
Dsh Bundle Declared

package.json declares DSH bundle metadata.

info
License Declared

GitHub reports the repository license as MIT.

info
Package Manifest Available

A root package.json was captured and can be inspected by the registry.

info
Source Available

Public GitHub source metadata is available for this registry snapshot.

info

Source & Registry Notes

Public provenance, Registry classification, and the latest source check for this entry, kept separate from runtime verification.

Source repository
lukepoo101/dsh-trusted-proxy-auth
Registry source
GitHub · dsh-plugin topic
Registry classification
Plugin
Source checked
a55496d · 2026-09-28

This project is independently indexed from public source information. DSH Plugin is not affiliated with DeepSeek or the plugin author. Always check the author repository before installation.

Repository Activity

GitHub stars
0GitHub stars
Forks
0
Open issues
0
Last commit
2026-09-25
Last release
2026-09-25
For maintainers

Maintaining this plugin?

This listing is generated from public repository data. If you maintain this project, you can review the information and share this listing with your users if you find it useful.

Add to README
Listed on DSHPlugin.app