dsh-lan-pair
内网配对远程访问:手机或另一台电脑扫码/令牌接入同一份 DSH Web 界面,支持内网免密钥直连。基于 @linxin666/dsh-remote-web-ui 0.4.4 改造,已彻底移除全部公网功能(Cloudflare 隧道、命名隧道、dsh-market 固定域名中继、遥测上报)。 适合需要通过手机或局域网其他设备安全访问界面的用户。
Install
$
npx -p @deepseek-ai/dsh dsh plugin --profile web add github:MyRemme/dsh-lan-pairREADME
Read the full README ↗配置
在 profile 的 cordis.patch.yml 中配置插件行:
- id: lan-pair
name: "dsh-lan-pair"
config:
lanBind: true # 把 Web 服务绑定改写为 0.0.0.0,并维护防火墙规则
allowLanWithoutKey: true # 内网设备无需配对/令牌直接打开界面
maxDevices: 32 # 已授权设备上限
idleExpireMs: 315360000000 # 设备空闲过期(毫秒)
# requirePairingForLan: true # 默认 true,通常无需显式设置
也可以在 DSH 的设置卡片里图形化调整这些开关。
关于「内网免密钥」与「局域网访问要求配对」的关系
内网免密钥的实现依赖门控的 /remote 通道——只有它会把内网请求送到 harness,并附上进程自身的凭据。因此:
allowLanWithoutKey: true时,插件会强制保留该通道,与requirePairingForLan取值无关;- 若两者都关,内网请求会走普通
/api,被 harness 的信任围栏挡为403。
这一点在实现里已做兜底,不会出现「界面能打开、但所有 API 全废」的情况。