dsh-cas
DeepSeek Harness (dsh) 插件: 用于实现CAS SSO单点登录 适合企业级部署中需要统一身份认证与单点登录的管理员。
Install
$
npx -p @deepseek-ai/dsh dsh plugin --profile web add github:awol2005ex3/dsh-casREADME
Read the full README ↗配置
在宿主 profile 的 ~/.dsh/settings.yaml 中,以插件 id cas 为键声明配置:
cas:
cas:
serverUrl: "http://sso.example.com"
loginPath: "/login"
validatePath: "/validate"
logoutPath: "/logout"
servicePath: "/cas/callback"
srcsys: "dsh"
tlsRejectUnauthorized: true
adminUsernames: ["admin1", "admin2"]
endpoints: # 可选:按客户端 IP 匹配多端点,首个匹配生效
- ipPattern: "10.251.%"
serverUrl: "http://sso-internal.example.com"
auth:
sessionTtlSeconds: 43200
cookieName: "dsh_cas_user"
cookieSameSite: "lax"
unownedSessions: "admin" # admin | everyone | none
adminOnlyMethods: [] # 额外限定管理员的 /api 方法
enforce: true
settings.yaml 中的 cas: 段经 ctx.settings 命名空间注册读取(src/index.ts 的 settings.register('cas', Config)),合并 schemastery 默认值与外挂 patch 的 config 后作为插件配置;改动后需重启宿主生效。管理员在页面 CAS 配置面板保存的设置会落盘到 $DSH_HOME/cas.yaml(store.ts),页面配置优先于 settings.yaml。
必填项:cas.serverUrl 或 cas.endpoints 至少其一。管理员角色由 cas.adminUsernames 中的 CAS 用户名(不区分大小写)映射得到。
环境变量
| 变量 | 说明 |
|---|---|
DSH_HOME | 数据根目录(缺省 ~/.dsh),状态文件位于 $DSH_HOME/cas.yaml |
DSH_SESSION_SECRET | 登录态签名密钥;不设置时进程启动随机生成(重启后需重新登录) |