ningbainb/deepseek-harness-desktop--packages-dsh-user-scope491

@ningbainb/dsh-user-scope

Shared user identity, workspace/session ownership, and device-scoped authorization for DeepSeek Harness plugins

AI 분석

适合需要为多插件提供统一的本地身份、设备授权及会话所有权校验的系统管理员。

패키지
@ningbainb/dsh-user-scope
버전
0.1.0
라이선스
BSD-3-Clause
최근 업데이트
2026. 9. 12.

설치

$npx -p @deepseek-ai/dsh dsh plugin --profile web add github:ningbainb/deepseek-harness-desktop#f30137e7d72942d2cd851a0fa0713f596ed06ad6&path:packages/dsh-user-scope

dsh-user-scope

English | 中文

@ningbainb/dsh-user-scope is the shared host-side authority for local profile identity, paired-device principals, Workspace grants, and Session ownership. It is intentionally UI-free so remote access, personal Prompt, memory, and future profile features use one authorization model.

The service listens to the official SessionStore lifecycle and rebuilds ownership for already-live sessions from the public WorkspaceRegistry projection; the memory plugin is not responsible for authorization writes.

Persistent state is kept below DSH_HOME/user-scope/ in private JSON files. Writes use the official atomic-write and file-lock SDKs. Unknown newer schema versions fail closed and are never rewritten by this package.

Security model

Local identity is an opaque random UUID-backed principal persisted in the current DSH profile. A remote device receives a separate paired principal; the client cannot select or submit its principal, owner, or grants. Remote Session access requires an active device binding, matching owner, and the corresponding Workspace grant when a Workspace is present. Local desktop access remains the administrative profile view.

Local desktop workspace access also checks actual registrations in the official WorkspaceRegistry, covering session creation before workspace attachment. This applies only to the current local principal; unknown workspaces, unavailable registries and remote devices retain the existing denial rules, and remote devices still require explicit grants.