Overview
dsh-web-app
Source-level overviewThe dsh browser-surface bundle. cordis.patch.yml rides over dsh-base: it sets the coding persona, inserts the Web host rows (webserver, API gateway, workspace, projection cache, storage) and the browser plugin roster, the always-on client-plugin reload chain (dsh-client-hmr, idle until a rebuild watcher rewrites client bundles), and mounts this package's web-runtime glue plugin (config {printUrl, surfaceContext, trustedHosts}). That plugin resolves the built frontend dist through @deepseek-ai/dsh-web-frontend's exports, samples bind-dependent LAN trust once, provides it as webRuntime to the browser-trust fence and client roster, mounts the frontend-static fallback owner, registers the harness-source and web-surface prompt sections plus the bash-visible DSH_WEB_URL runtime variable when surfaceContext is true, and prints the dsh web: URL line when printUrl is true, after its Loader tree settles so a sibling failure cannot announce a dead app. This bundle also owns the app command line: the ordinary web-startup provider (src/startup.ts) injects ctx.cmdlineArgs (dsh-cmdline), parses --host, --port, repeatable --trusted-host, and the app's --help, then provides webStartup. It rejects --host 0.0.0.0 before publishing that service because the CLI intentionally does not support all-interfaces binding yet. Flag-configured rows inject the service and read it directly from lazy config, so nothing binds a port before argument resolution and dsh --profile web --help starts no server. dsh-headless is a sibling surface over the same base and does not mount this bundle.Collapse technical overview
cordis.patch.yml rides over dsh-base: it sets the coding persona, inserts the Web host rows (webserver, API gateway, workspace, projection cache, storage) and the browser plugin roster, the always-on client-plugin reload chain (dsh-client-hmr, idle until a rebuild watcher rewrites client bundles), and mounts this package's web-runtime glue plugin (config {printUrl, surfaceContext, trustedHosts}). That plugin resolves the built frontend dist through @deepseek-ai/dsh-web-frontend's exports, samples bind-dependent LAN trust once, provides it as webRuntime to the browser-trust fence and client roster, mounts the frontend-static fallback owner, registers the harness-source and web-surface prompt sections plus the bash-visible DSH_WEB_URL runtime variable when surfaceContext is true, and prints the dsh web: URL line when printUrl is true, after its Loader tree settles so a sibling failure cannot announce a dead app. This bundle also owns the app command line: the ordinary web-startup provider (src/startup.ts) injects ctx.cmdlineArgs (dsh-cmdline), parses --host, --port, repeatable --trusted-host, and the app's --help, then provides webStartup. It rejects --host 0.0.0.0 before publishing that service because the CLI intentionally does not support all-interfaces binding yet. Flag-configured rows inject the service and read it directly from lazy config, so nothing binds a port before argument resolution and dsh --profile web --help starts no server. dsh-headless is a sibling surface over the same base and does not mount this bundle.The dsh.bundle manifest proves this is a DSH profile activation layer; it does not prove the Git subdirectory is independently installable.
Capabilities
What it contributes
README / EN
Package documentation
@deepseek-ai/dsh-web-app
English | 中文
The dsh browser-surface bundle. cordis.patch.yml rides over dsh-base: it sets the coding persona, inserts the Web host rows (webserver, API gateway, workspace, projection cache, storage) and the browser plugin roster, the always-on client-plugin reload chain (dsh-client-hmr, idle until a rebuild watcher rewrites client bundles), and mounts this package's web-runtime glue plugin (config {printUrl, surfaceContext, trustedHosts}). That plugin resolves the built frontend dist through @deepseek-ai/dsh-web-frontend's exports, samples bind-dependent LAN trust once, provides it as webRuntime to the browser-trust fence and client roster, mounts the frontend-static fallback owner, registers the harness-source and web-surface prompt sections plus the bash-visible DSH_WEB_URL runtime variable when surfaceContext is true, and prints the dsh web: URL line when printUrl is true, after its Loader tree settles so a sibling failure cannot announce a dead app. This bundle also owns the app command line: the ordinary web-startup provider (src/startup.ts) injects ctx.cmdlineArgs (dsh-cmdline), parses --host, --port, repeatable --trusted-host, and the app's --help, then provides webStartup. It rejects --host 0.0.0.0 before publishing that service because the CLI intentionally does not support all-interfaces binding yet. Flag-configured rows inject the service and read it directly from lazy config, so nothing binds a port before argument resolution and dsh --profile web --help starts no server. dsh-headless is a sibling surface over the same base and does not mount this bundle.
Model Experience
Harness-source and Web-surface context
What the model sees
When surfaceContext is true, the harness:source section identifies the on-disk Harness implementation without claiming it is the working directory, and the app:web-surface global section (order −98) orients the model to the GUI: the canonical local URL, the "this page" referent, the update contract (the reload receiver is always on; no-refresh reloads additionally need the pnpm run dev:web watcher), and the instruction not to start replacement servers. DSH_WEB_URL additionally appears in the managed bash environment with its description, resolved per invocation from the live server. When it is false, neither section nor the variable is registered.
Token effect
One source line and one prompt paragraph per session plus two managed-environment variable lines; constant per process.
KV Cache effect
The prompt section sits near the system prompt's head and is stable for the life of the process (the port is a boot fact), so it does not invalidate the cache across turns.
Known Limitations and Deferred Work
- The frontend dist must be built —
require.resolveof the dist fails loud at activation with a build hint; there is no source-serving fallback. lanAddressesis a boot-time snapshot — interface changes after boot are not re-advertised; the printed LAN URL always matches the configured trust fence.
LIMITATIONS
Known limitations
- **The frontend dist must be built** — `require.resolve` of the dist fails loud at activation with a build hint; there is no source-serving fallback. - **`lanAddresses` is a boot-time snapshot** — interface changes after boot are not re-advertised; the printed LAN URL always matches the configured trust fence.
