idoall/dsh-lan-guard ↗★ 0

dsh-lan-guard

DSH web plugin: expose the official desktop Web UI to the local network through a gated reverse proxy, without touching DSH's own loopback binding. 适合需要通过手机等局域网设备安全访问桌面端UI的用户。

패키지
dsh-lan-guard
호환성
미검증
Harness peer 범위
>=0.1.7-rc.1 <0.2.0
Cordis peer 범위
^4.0.4
버전
0.2.0
라이선스
MIT
최근 업데이트
2026. 9. 25.

설치

$npx -p @deepseek-ai/dsh dsh plugin --profile web add github:idoall/dsh-lan-guard

Usage

  1. In Settings → 局域网访问 → 安全认证, set an access password (at least 8 characters). Until you do, the gate refuses every device.
  2. In 连接与证书, pick the NIC to publish on. 0.0.0.0 is the default for a configured plugin; set listenHost: 127.0.0.1 in the config to keep it local-only while you try it out.
  3. Open the 扫码访问 tab and scan the QR code with your phone.
  4. On the phone: trust the DSH LAN Guard CA certificate (the SHA-256 fingerprint is shown in the settings page), enter the access password once, then name the device on the pairing page.
  5. The phone now runs the official DSH UI. It appears under 已授权设备, where you can revoke it at any time.

Remote devices are read-only by default (adminPolicy: local_only): they can use DSH but cannot change plugin settings. Switch the policy on the desktop if you want a phone to manage them.

Configuration

The plugin reads its config from its Cordis entry (profile patch or dsh plugin config). Defaults are conservative: nothing is published until you say so.

enabled: true                    # master switch
listenHost: 0.0.0.0              # default 127.0.0.1 (loopback only); set to face the LAN
listenPort: 3081                 # DSH port + 1; auto-walks up to 10 ports when taken
upstreamOrigin: http://127.0.0.1:3080
dataDir: ~/.dsh/profiles/web/data/dsh-lan-guard
networkInterface: en0            # optional: publish on one NIC (empty = automatic)
tls:
  mode: self-signed              # 'self-signed' (default) | 'provided' | 'off'
  allowInsecureLan: false        # required acknowledgement for LAN plain HTTP
mdns:
  enabled: false                 # advertise _dsh-lan-guard._tcp
auth:
  mode: token_and_password       # 'token_and_password' | 'password' | 'token'
  adminPolicy: local_only        # 'local_only' (default) | 'password_unlock' | 'open'
  adminProtection: true          # admin console needs the admin password
  allowLoopback: true            # 127.0.0.1 visitors skip the gate (physically unlocked)
  requirePairing: true           # new remote devices must name themselves once

Every key above can also be changed from the settings page (the non-sensitive ones are declared as volatile config fields).