ningbainb/deepseek-harness-desktop--packages-dsh-user-scope ↗★ 491
@ningbainb/dsh-user-scope
共享用户身份与会话所有权管理
AI 分析
适合需要为多插件提供统一的本地身份、设备授权及会话所有权校验的系统管理员。
安裝
npx -p @deepseek-ai/dsh dsh plugin --profile web add github:ningbainb/deepseek-harness-desktop#f30137e7d72942d2cd851a0fa0713f596ed06ad6&path:packages/dsh-user-scope說明文件
閱讀完整 README ↗dsh-user-scope
English | 中文
@ningbainb/dsh-user-scope is the shared host-side authority for local
profile identity, paired-device principals, Workspace grants, and
Session ownership. It is intentionally UI-free so remote access, personal
Prompt, memory, and future profile features use one authorization model.
The service listens to the official SessionStore lifecycle and rebuilds
ownership for already-live sessions from the public WorkspaceRegistry
projection; the memory plugin is not responsible for authorization writes.
Persistent state is kept below DSH_HOME/user-scope/ in private JSON files.
Writes use the official atomic-write and file-lock SDKs. Unknown newer schema
versions fail closed and are never rewritten by this package.
Security model
Local identity is an opaque random UUID-backed principal persisted in the current DSH profile. A remote device receives a separate paired principal; the client cannot select or submit its principal, owner, or grants. Remote Session access requires an active device binding, matching owner, and the corresponding Workspace grant when a Workspace is present. Local desktop access remains the administrative profile view.
Local desktop workspace access also checks actual registrations in the official WorkspaceRegistry, covering session creation before workspace attachment. This applies only to the current local principal; unknown workspaces, unavailable registries and remote devices retain the existing denial rules, and remote devices still require explicit grants.