Skip to content
dsh.fish
Bundle

dsh-lan-gate

Password + CIDR gate for DeepSeek Harness web / DeepSeek Harness 局域网密码门禁

Source
maxesisnclaw
License
MIT
Updated
Updated 2 days ago

Readme

# dsh-lan-gate

English | [中文](README.zh.md)

Password gate + CIDR allowlist + proxy-header deny for [DeepSeek Harness](https://github.com/deepseek-ai/deepseek-harness) web.

`dsh web --host 0.0.0.0` is rejected by the CLI. This bundle sets `webserver.host` to `0.0.0.0` through the official composition layer, then requires a password before the UI or `/api` is reachable from the LAN.

## Install

```sh
dsh plugin --profile web add dsh-lan-gate
```

Or from GitHub:

```sh
dsh plugin --profile web add github:maxesisnclaw/dsh-lan-gate
```

Then open `http://127.0.0.1:3080/dsh-lan-full/login` and set a password (loopback only). After that, LAN clients get the login page.

Settings → **LAN access** / **LAN 访问** edits CIDRs, proxy-header policy, and the password. The settings section and login page follow dsh's official `zh`/`en` locale.

## What it does

| Control | Default |
|---|---|
| Listen on all interfaces | yes (bundle patch) |
| Password | unset until you set it from loopback |
| Inbound IPv4 CIDRs | `10.0.0.0/8`, `172.16.0.0/12`, `192.168.0.0/16` |
| Reject `X-Forwarded-*` / `Forwarded` / `Via` | yes |
| Loopback bypasses password | yes (recovery) |

Policy file: `$DSH_HOME/lan-gate.json` (mode `0600`). The password is stored as a scrypt verifier, never as plaintext. Session tokens are random 32-byte values; only their SHA-256 is kept in memory.

## Residual risk

This is not a TLS terminator. On plain HTTP a LAN observer can still sniff the password and cookie. Do not put this on the public internet. Do not sit it behind a reverse proxy that adds forwarding headers — those requests are rejected on purpose.

See [SECURITY.md](SECURITY.md).

## License

MIT

Install

dsh plugin --profile web add github:maxesisnclaw/dsh-lan-gate#ec3cc4b0389cf3e9dbcb14626b645a693d56b54d

Profile: web

Source