dsh-trusted-proxy-auth
DeepSeek Harness plugin providing trusted reverse proxy authentication alongside native browser auth fallback.
Install
$ dsh plugin --profile web add /path/to/dsh-trusted-proxy-authPlugin Overview & Capabilities
AI-assisted organization based on the public repository snapshot. The content must be grounded in source evidence and does not replace compatibility or security verification.
Key Capabilities
- Validates private shared secret headers from upstream reverse proxies using timing-safe comparisons
- Preserves native DeepSeek Harness browser token and cookie authentication as a fallback
- Maintains Host and Origin fencing to prevent DNS rebinding and cross-site request attacks
- Injects client-side transport ownsHost bootstrap to maintain host settings persistence across remote origins
- Performs fail-closed startup validation to verify runtime auth semantics before booting
Useful For
- Securing DeepSeek Harness behind Traefik, Keycloak OIDC, or similar enterprise reverse proxies
- Allowing remote operator access via corporate single sign-on without breaking emergency local SSH access
- Persisting Model catalog and Plugin configurations when accessing DSH from non-loopback domains
Who It Fits
- DevOps engineers deploying DeepSeek Harness in containerized or Kubernetes environments
- System administrators integrating DSH with corporate single sign-on (OIDC) identity providers
- Security-focused operators seeking defence-in-depth auth boundaries
Documented Limitations
- Requires an isolated network or TLS between the reverse proxy and DSH to prevent secret sniffing
- Does not handle OIDC or JWT token parsing directly, relying on the upstream proxy to perform authentication
- Fails loudly on startup if DSH_PROXY_AUTH_SECRET is absent, malformed, or shorter than 32 bytes
DSH Compatibility
Version-specific runtime evidence collected by DSH Plugin. A missing result means we have not tested that combination yet.
Security Signals
Objective signals discovered from package metadata and source inspection. These are not a guarantee that a plugin is safe.
package.json declares 0 runtime, 0 development, 0 peer, and 0 optional dependencies.
package.json declares DSH bundle metadata.
GitHub reports the repository license as MIT.
A root package.json was captured and can be inspected by the registry.
Public GitHub source metadata is available for this registry snapshot.
Source & Registry Notes
Public provenance, Registry classification, and the latest source check for this entry, kept separate from runtime verification.
- Source repository
- lukepoo101/dsh-trusted-proxy-auth
- Registry source
- GitHub · dsh-plugin topic
- Registry classification
- Plugin
- Source checked
- a55496d · 2026-09-28
This project is independently indexed from public source information. DSH Plugin is not affiliated with DeepSeek or the plugin author. Always check the author repository before installation.
Repository Activity
- GitHub stars
- 0GitHub stars
- Forks
- 0
- Open issues
- 0
- Last commit
- 2026-09-25
- Last release
- 2026-09-25
Related DSH Plugins
Ranked by overlapping capabilities, use cases, plugin type, categories, and DSH profile.
Compatibility bridge and host ABI enabling unmodified Pi plugins to run natively on DeepSeek Harness.
View plugin →Preview, create, and edit spreadsheets, docs, slides, and canvases in DeepSeek Harness powered by Univer.
View plugin →Persistent multi-model Agent teams and bounded DAG workflows with GUI controls for DeepSeek Harness.
View plugin →Second-model AI auto-review for DeepSeek Harness approval requests with fail-closed safety and session audit.
View plugin →