dsh-lan-guard
通过安全反向代理将桌面端网页服务发布至局域网 适合需要通过手机等局域网设备安全访问桌面端UI的用户。
安裝
$
npx -p @deepseek-ai/dsh dsh plugin --profile web add github:idoall/dsh-lan-guard說明文件
閱讀完整 README ↗Usage
- In Settings → 局域网访问 → 安全认证, set an access password (at least 8 characters). Until you do, the gate refuses every device.
- In 连接与证书, pick the NIC to publish on.
0.0.0.0is the default for a configured plugin; setlistenHost: 127.0.0.1in the config to keep it local-only while you try it out. - Open the 扫码访问 tab and scan the QR code with your phone.
- On the phone: trust the
DSH LAN Guard CAcertificate (the SHA-256 fingerprint is shown in the settings page), enter the access password once, then name the device on the pairing page. - The phone now runs the official DSH UI. It appears under 已授权设备, where you can revoke it at any time.
Remote devices are read-only by default (
adminPolicy: local_only): they can use DSH but cannot change plugin settings. Switch the policy on the desktop if you want a phone to manage them.
Configuration
The plugin reads its config from its Cordis entry (profile patch or dsh plugin config). Defaults are conservative: nothing is published until you say so.
enabled: true # master switch
listenHost: 0.0.0.0 # default 127.0.0.1 (loopback only); set to face the LAN
listenPort: 3081 # DSH port + 1; auto-walks up to 10 ports when taken
upstreamOrigin: http://127.0.0.1:3080
dataDir: ~/.dsh/profiles/web/data/dsh-lan-guard
networkInterface: en0 # optional: publish on one NIC (empty = automatic)
tls:
mode: self-signed # 'self-signed' (default) | 'provided' | 'off'
allowInsecureLan: false # required acknowledgement for LAN plain HTTP
mdns:
enabled: false # advertise _dsh-lan-guard._tcp
auth:
mode: token_and_password # 'token_and_password' | 'password' | 'token'
adminPolicy: local_only # 'local_only' (default) | 'password_unlock' | 'open'
adminProtection: true # admin console needs the admin password
allowLoopback: true # 127.0.0.1 visitors skip the gate (physically unlocked)
requirePairing: true # new remote devices must name themselves once
Every key above can also be changed from the settings page (the non-sensitive ones are declared as volatile config fields).