idoall/dsh-lan-guard ↗★ 0

dsh-lan-guard

通过安全反向代理将桌面端网页服务发布至局域网 适合需要通过手机等局域网设备安全访问桌面端UI的用户。

包名
dsh-lan-guard
兼容性
待验证
Harness 依赖范围
>=0.1.7-rc.1 <0.2.0
Cordis 依赖范围
^4.0.4
版本
0.2.0
许可证
MIT
最近更新
2026年9月25日

安装

$npx -p @deepseek-ai/dsh dsh plugin --profile web add github:idoall/dsh-lan-guard

Usage

  1. In Settings → 局域网访问 → 安全认证, set an access password (at least 8 characters). Until you do, the gate refuses every device.
  2. In 连接与证书, pick the NIC to publish on. 0.0.0.0 is the default for a configured plugin; set listenHost: 127.0.0.1 in the config to keep it local-only while you try it out.
  3. Open the 扫码访问 tab and scan the QR code with your phone.
  4. On the phone: trust the DSH LAN Guard CA certificate (the SHA-256 fingerprint is shown in the settings page), enter the access password once, then name the device on the pairing page.
  5. The phone now runs the official DSH UI. It appears under 已授权设备, where you can revoke it at any time.

Remote devices are read-only by default (adminPolicy: local_only): they can use DSH but cannot change plugin settings. Switch the policy on the desktop if you want a phone to manage them.

Configuration

The plugin reads its config from its Cordis entry (profile patch or dsh plugin config). Defaults are conservative: nothing is published until you say so.

enabled: true                    # master switch
listenHost: 0.0.0.0              # default 127.0.0.1 (loopback only); set to face the LAN
listenPort: 3081                 # DSH port + 1; auto-walks up to 10 ports when taken
upstreamOrigin: http://127.0.0.1:3080
dataDir: ~/.dsh/profiles/web/data/dsh-lan-guard
networkInterface: en0            # optional: publish on one NIC (empty = automatic)
tls:
  mode: self-signed              # 'self-signed' (default) | 'provided' | 'off'
  allowInsecureLan: false        # required acknowledgement for LAN plain HTTP
mdns:
  enabled: false                 # advertise _dsh-lan-guard._tcp
auth:
  mode: token_and_password       # 'token_and_password' | 'password' | 'token'
  adminPolicy: local_only        # 'local_only' (default) | 'password_unlock' | 'open'
  adminProtection: true          # admin console needs the admin password
  allowLoopback: true            # 127.0.0.1 visitors skip the gate (physically unlocked)
  requirePairing: true           # new remote devices must name themselves once

Every key above can also be changed from the settings page (the non-sensitive ones are declared as volatile config fields).