All plugins

DSH / BUNDLE / CLIENT-UI

dsh-rgate

v0.3.1raomaiping-hash / dsh-rgate9251a8935d

InstallableBundlesUI & client pluginsCommunity · Topic auto-analysisWeb UI

Overview

dsh-rgate

Remote access login gate for the DeepSeek Harness Web UI: a password wall in front of non-loopback access, session cookies, an injected browser-side gate, and a Remote Access settings section. The /api RPC surface is authenticated by dsh itself.

README / EN

Package documentation

Registry summary

Remote access login gate for the DeepSeek Harness Web UI: a password wall in front of non-loopback access, session cookies, an injected browser-side gate, and a Remote Access settings section. The /api RPC surface is authenticated by dsh itself.

dsh.pub verifies the pinned bundle contract, runtime facts, and distribution semantics. The complete README remains in the source repository.

Read the full README on GitHub

LIMITATIONS

Known limitations

- **WebSocket event streams are not gated.** `/api/events.mux` and `/api/events.host` upgrades are owned by the shipped `dsh-client-connection` plugin; registering the same upgrade path throws, and pre-registering breaks boot. A fence-passing client can still open them and receive live session event frames. The robust fix is **upstream**: enable Cloudflare Access (Zero Trust) on your public domain, or put an authenticating reverse proxy (e.g. nginx `auth_request`) in front. That closes UI, API and WebSockets before traffic reaches the Harness. - **The `/api` method table is not owned here.** Harness-native `/api` authentication (no credentials → `401`) covers new RPCs as they are added; rgate never shadows that table. - **Sessions are in-memory.** A Harness restart signs everyone out (7-day cookie otherwise). - Static assets are still served to unauthenticated visitors (they are public code); all data lives behind the API gate.