All plugins

DSH / BUNDLE / CLIENT-UI

dsh-auth-gate

v0.15.0TecFancy / dsh-auth-gate4f362a723a

InstallableBundlesUI & client pluginsCommunity · Topic auto-analysisWeb UI

Overview

dsh-auth-gate

Login gate for DeepSeek Harness (dsh) web instances: password or shared-token sign-in, optional TOTP two-factor, session cookies, rate limiting, self-service password change and a user-management CLI

README / EN

Package documentation

Registry summary

Login gate for DeepSeek Harness (dsh) web instances: password or shared-token sign-in, optional TOTP two-factor, session cookies, rate limiting, self-service password change and a user-management CLI

dsh.pub verifies the pinned bundle contract, runtime facts, and distribution semantics. The complete README remains in the source repository.

Read the full README on GitHub

LIMITATIONS

Known limitations

The short list; the full version, including the mechanisms and the ADRs behind them, is in `docs/deployed/known-limitations.md`. - Disabling a user only stops **new** logins; sessions already issued are revoked by the periodic sweep (`revokeSweepMs`, 5 s by default - with `0` they stay valid until they expire). - Login rate limiting and the TOTP replay guard reset when the server restarts. - Behind a reverse proxy, set `clientIpHeader` (and `trustedProxyCidrs`): otherwise all clients share one lockout bucket, and login plus the self-service change each have their own, so both are affected. - A password change reports success even if revoking the old sessions fails; the failure is logged at error level and the old cookie stays valid until its session TTL. - The plugin protects dsh's web surface only. Keep the OS user and the config files private.