dsh-webui-auth
DeepSeek Harness WebUI authentication bundle that gates web resources, plugin bundles, API RPC, and WebSocket connections behind login.
Install
$ 维护者开发模式:在本地源码目录使用 dsh plugin --profile web add ./dsh-webui-auth(link: 安装),改代码 → 重启 DSH 即生效,无需重新安装。Plugin Overview & Capabilities
AI-assisted organization based on the public repository snapshot. The content must be grounded in source evidence and does not replace compatibility or security verification.
Key Capabilities
- Installs through the DSH plugin command as an npm, GitHub, or local-source bundle.
- Gates WebUI resources, /plugins bundles, /api RPC requests, and specified WebSocket upgrade requests.
- Provides login and authentication settings pages for creating, changing, disabling, and ending authentication.
- Stores password credentials using scrypt and keeps sessions in server memory.
- Supports configurable session durations and revokes other sessions after a password change.
- Records authentication-related events in an audit.jsonl file and provides CLI and settings-page views.
- Detects missing core-package patches and attempts to reapply them when patch anchors match.
Useful For
- Require a login before users can access a DSH WebUI deployment.
- Add a local authentication gate for WebUI resources, APIs, and real-time event connections.
- Review recent login and configuration events through audit logs.
Who It Fits
- DeepSeek Harness operators running the web profile.
- Administrators who want a login gate for a locally hosted DSH WebUI.
Documented Limitations
- Authentication remains disabled until an administrator creates credentials.
- Sessions are stored only in process memory, so all sessions expire when DSH restarts.
- The plugin modifies core DSH client packages; after a DSH upgrade, an automatically reapplied patch requires another restart to take effect in the running process.
- Automatic patch recovery can fail if core-package structure or anchors change.
- The documented threat model excludes local processes able to directly read or write host process memory or files.
- Some registered exact configuration endpoints are explicitly excluded from the gate.
DSH Compatibility
Version-specific runtime evidence collected by DSH Plugin. A missing result means we have not tested that combination yet.
Security Signals
Objective signals discovered from package metadata and source inspection. These are not a guarantee that a plugin is safe.
package.json declares 0 runtime, 0 development, 0 peer, and 0 optional dependencies.
package.json declares DSH bundle metadata.
GitHub reports the repository license as MIT.
A root package.json was captured and can be inspected by the registry.
Public GitHub source metadata is available for this registry snapshot.
Source & Registry Notes
Public provenance, Registry classification, and the latest source check for this entry, kept separate from runtime verification.
- Source repository
- Yuuz12/dsh-webui-auth
- Registry source
- GitHub · dsh-plugin topic
- Registry classification
- Plugin Bundle
- Source checked
- 5cc72a8 · 2026-09-17
This project is independently indexed from public source information. DSH Plugin is not affiliated with DeepSeek or the plugin author. Always check the author repository before installation.
Repository Activity
- GitHub stars
- 8GitHub stars
- Forks
- 3
- Open issues
- 0
- Last commit
- 2026-09-16
- Last release
- No release detected
Related DSH Plugins
Ranked by overlapping capabilities, use cases, plugin type, categories, and DSH profile.
Local-first AI agent runtime and DSH plugin bundle providing sandboxed sessions, MCP tools, audit logs, and session replay.
View plugin →Compatibility bridge and host ABI enabling unmodified Pi plugins to run natively on DeepSeek Harness.
View plugin →Mobile companion and secure remote/LAN access plugin for DeepSeek Harness.
View plugin →Real-time market research cockpit and MCP bundle for DeepSeek Harness financial and macro data.
View plugin →