概览
dsh-auth-gate
README / ZH
插件文档
目录摘要
dsh.pub 核对固定版本的组合包契约、运行时事实与分发语义;完整 README 请查看源仓库。
在 GitHub 阅读完整 READMELIMITATIONS
已知限制
The short list; the full version, including the mechanisms and the ADRs behind them, is in `docs/deployed/known-limitations.md`. - Disabling a user only stops **new** logins; sessions already issued are revoked by the periodic sweep (`revokeSweepMs`, 5 s by default - with `0` they stay valid until they expire). - Login rate limiting and the TOTP replay guard reset when the server restarts. - Behind a reverse proxy, set `clientIpHeader` (and `trustedProxyCidrs`): otherwise all clients share one lockout bucket, and login plus the self-service change each have their own, so both are affected. - A password change reports success even if revoking the old sessions fails; the failure is logged at error level and the old cookie stays valid until its session TTL. - The plugin protects dsh's web surface only. Keep the OS user and the config files private.
