Bundle
dsh-qr-phone-login
Show a secure QR code to sign a phone into this DSH
- Source
- yoggu
- License
- MIT
- Updated
- Updated 21 hours ago
Readme
# dsh-qr-phone-login Adds a **Plugins → QR phone login** page to DSH Web. A signed-in user can display a QR code that opens the same DSH installation on a phone and signs it in using DSH's launch-token mechanism. ## Install Install the tagged GitHub release into your DSH Web profile: ```sh dsh plugin --profile web add 'https://github.com/yoggu/dsh-qr-phone-login.git#v0.1.1' ``` Or download the source and link the local checkout: ```sh git clone --branch v0.1.1 --depth 1 https://github.com/yoggu/dsh-qr-phone-login.git cd dsh-qr-phone-login pnpm install dsh plugin --profile web add "link:$(pwd)" ``` Keep a linked checkout in place while the plugin is installed. Use the profile you actually run if it is not `web`. Restart DSH Web if necessary and reload the page. Configure `publicOrigin` on the plugin page to the **HTTPS origin actually served to the phone** (for example `https://dsh.example.com`), with no path or query. The plugin does not set up HTTPS, DNS, Tailscale or a reverse proxy. The phone must be able to reach that origin. To uninstall: `dsh plugin --profile web remove dsh-qr-phone-login`. ## Security **Anyone who sees or photographs the displayed QR code can sign in with the same access.** Display it privately; do not share screenshots, logs or SVG responses. The SVG route is protected by DSH's existing browser authentication and Origin checks, and the plugin does not put the launch token into configuration. The token encoded in the QR code is process-wide and reusable until the DSH process restarts; this plugin cannot make it one-time or short-lived. Restart DSH to rotate it if exposed. DSH login cookies can remain valid after that restart until their configured expiry (30 days by default); revoke affected sessions separately where supported. This is suitable only for trusted installations and users. ## Tests and license Run `npm test` after installing the DSH peer dependencies. MIT; see [LICENSE](LICENSE).
Install
dsh plugin --profile web add github:yoggu/dsh-qr-phone-login
Profile: web
With the hub plugin installed, ask your agent to install it by name — it resolves the same plan shown here.
dsh plugin --profile web add github:stvlynn/dsh.fish#path:packages/dsh-plugin-hub
install dsh-qr-phone-login from the hub
- This source has no pinned commit, so a later push upstream changes what installs. Prefer pinning a commit.