xarleyn/dsh-plugins--plugins-dsh-web-fetch-authenticated ↗★ 1

@yadsh/dsh-web-fetch-authenticated

提供带鉴权与策略控制的受限抓取通道,用于受保护站点访问 适合需要访问受限网页的检索任务,需先配置凭据与主机可达的匹配规则。

套件
@yadsh/dsh-web-fetch-authenticated
相容性
待驗證
Harness 依賴範圍
catalog:dsh
Cordis 依賴範圍
catalog:dsh
版本
0.2.0
授權
MIT
最近更新
2026年9月13日

安裝

$npx -p @deepseek-ai/dsh dsh plugin --profile web add github:xarleyn/dsh-plugins#fd3cdd95651ec4eafe52d510751ba3aba3c9248d&path:plugins/dsh-web-fetch-authenticated

Configuration

Everything is editable from the DSH Web UI (Settings → Plugins → Authenticated Web Fetch): rules, credential write-only fields, network policy, redirects, limits, connection tester, and diagnostics. Declarative config stays available:

- id: web
  config:
    fetchProvider: authenticated

- id: web-fetch-authenticated
  name: '@yadsh/dsh-web-fetch-authenticated'
  config:
    rules:
      - id: corp-jira
        name: Corporate Jira
        enabled: true
        testUrl: https://jira.example.corp/status
        match:
          hosts: [jira.example.corp]
          allowPaths: [/browse/**, /rest/api/**]
        auth:
          type: bearer
          credential: JIRA_TOKEN        # credential REFERENCE, not the secret
        networkPolicy:
          allowPrivate: true
          allowedCidrs: [10.40.0.0/16]
        redirects:
          mode: same-origin
          maxRedirects: 3

- id: tool-web
  name: '@deepseek-ai/dsh-tool-web'
  config:
    fetch: true

Secrets are stored through the DSH credential store ($DSH_HOME credential backend) under POSIX-style reference names (JIRA_TOKEN); configuration keeps only the reference. Use the UI (or api.credentials.set) to store the value.

Security defaults

PolicyDefault
SchemesHTTPS only (per-rule http opt-in warns)
Private networks / loopback / link-local / CGNAT / IPv6 ULAdenied
Cloud metadata (169.254.169.254, fd00:ec2::254)always denied
Redirectssame-origin only, max 3
Timeout / response size / body chars30 s / 5 MiB / 100 k chars
Unmatched URLsblocked (strict)

Narrow allowedCidrs are preferred over blanket allowPrivate: true. DNS answers are resolved, all candidates are classified, one denied answer denies the whole set (DNS-rebinding defense), and the socket is pinned to the approved addresses.