Skip to content
dsh.fish
Bundle

dsh-qqbot-panel

Visual web settings panel for the official @tencent-connect/dsh-qqbot plugin: manage the QQ Bot AppID/AppSecret, c2c & group access modes/allowlists, cwd and requireMention directly in the DSH web settings page (reads/writes the qqbot profile's cordis.patch.yml).

Source
zhengjy01
License
MIT
Updated
Updated yesterday

Readme

# dsh-qqbot-panel

> **English** | [**中文**](README.zh.md)

A visual settings panel for the official [@tencent-connect/dsh-qqbot](https://github.com/tencent-connect/dsh-qqbot) plugin for [DeepSeek Harness](https://github.com/deepseek-ai/deepseek-harness) (dsh). The official QQ bot plugin is a pure CLI plugin with no Web UI; this companion plugin adds a **Settings → QQ Bot** page so you can configure everything — and even bind your bot by scanning a QR code — right from the web GUI.

## Features

- **Settings panel** — web GUI: Settings → QQ Bot. Manage `appId` / `appSecret`, private-chat (c2c) & group access modes (`open` / `allowlist` / `disabled`) and their allowlists, `requireMention`, and the agent working directory.
- **Scan-to-bind** — one click generates a QR code inside the panel; scan it with the QQ app and the returned `appId` / `appSecret` are written back automatically (no browser connect page, no Apple-ID login).
- **Workspace picker** — choose which workspace the QQ bot's agent sessions live in (`cwd`); the panel lists every workspace that already has sessions and its session count.
- Reads/writes the `im-qqbot` row in the qqbot profile's `cordis.patch.yml` via a loopback-only `/api/dsh-qqbot-panel` route family.
- `appSecret` is only ever returned masked and is never overwritten by an empty value.

## Companion / dependency

This is a **companion panel** for the [official QQ bot plugin](https://github.com/tencent-connect/dsh-qqbot) (`@tencent-connect/dsh-qqbot`). That plugin must be installed and bound to a QQ bot for this panel to be useful — the panel edits the same `cordis.patch.yml` the QQ bot profile loads.

Runtime `dependencies` (installed automatically): `@tencent-connect/qqbot-connector`, `qrcode`, `js-yaml`.

## Install

```sh
# after publishing (repo tagged with the `dsh-plugin` topic)
dsh plugin --profile web add github:zhengjy01/dsh-qqbot-panel

# local development
dsh plugin --profile web add link:/path/to/dsh-qqbot-panel
```

Then restart `dsh web` and open **Settings → QQ Bot**. The plugin needs no build step — `lib/index.js` is plain ESM.

## Used with

```sh
# the official QQ bot plugin (required companion), in its own profile
dsh plugin --profile qqbot add @tencent-connect/dsh-qqbot
dsh --profile qqbot          # prints a QR to bind, or use the panel's scan-to-bind
```

## Configuration

Everything is managed from the panel: Settings → QQ Bot. There you can set `appId` / `appSecret`, the access modes and allowlists, whether group chats need `@bot` (`requireMention`), and the workspace the QQ bot sessions land in.

The panel persists changes to the qqbot profile's `cordis.patch.yml` (`~/.dsh/profiles/qqbot/cordis.patch.yml`), which the running QQ bot hot-reloads.

## Notes

- The `/api/dsh-qqbot-panel` routes are loopback-only (browser same-origin only).
- The scan-to-bind flow uses the QQ bot connect task; the returned `appId`/`appSecret` are stored with mode `0600` in the qqbot profile config.
- Logo / branding intentionally minimal; the panel uses plain inline styles and no external UI kit.

## License

MIT

Install

dsh plugin --profile web add github:zhengjy01/dsh-qqbot-panel

Profile: web

  • This package builds from source on install. pnpm will ask you to allow its build script — that is permission to run the package’s code on your machine, outside the agent sandbox. Only allow sources you trust.
  • This source has no pinned commit, so a later push upstream changes what installs. Prefer pinning a commit.
Source