概览
dsh-rgate
README / ZH
插件文档
目录摘要
dsh.pub 核对固定版本的组合包契约、运行时事实与分发语义;完整 README 请查看源仓库。
在 GitHub 阅读完整 READMELIMITATIONS
已知限制
- **WebSocket event streams are not gated.** `/api/events.mux` and `/api/events.host` upgrades are owned by the shipped `dsh-client-connection` plugin; registering the same upgrade path throws, and pre-registering breaks boot. A fence-passing client can still open them and receive live session event frames. The robust fix is **upstream**: enable Cloudflare Access (Zero Trust) on your public domain, or put an authenticating reverse proxy (e.g. nginx `auth_request`) in front. That closes UI, API and WebSockets before traffic reaches the Harness. - **The `/api` method table is not owned here.** Harness-native `/api` authentication (no credentials → `401`) covers new RPCs as they are added; rgate never shadows that table. - **Sessions are in-memory.** A Harness restart signs everyone out (7-day cookie otherwise). - Static assets are still served to unauthenticated visitors (they are public code); all data lives behind the API gate.
