Skip to content
dsh.fish
Bundle

@woyeshishen/dsh-lan-access

为 DeepSeek Harness 提供局域网访问能力:绑定 0.0.0.0 并注入 crypto.randomUUID polyfill,使纯 HTTP 局域网源下 GUI 与 /api 正常工作,不改动任何原始代码。

Source
woyeshishen
License
Apache-2.0
Updated
Updated 3 days ago

Readme

# dsh-lan-access

[![npm version](https://img.shields.io/npm/v/@woyeshishen/dsh-lan-access)](https://www.npmjs.com/package/@woyeshishen/dsh-lan-access)
[![license](https://img.shields.io/npm/l/@woyeshishen/dsh-lan-access)](LICENSE)

[中文](README.zh.md) | English

Bind the [DeepSeek Harness](https://github.com/deepseek-ai/deepseek-harness) (DSH) Web GUI to `0.0.0.0` so other machines on the LAN can reach it — plus a `crypto.randomUUID` polyfill that makes the GUI fully work over plain-HTTP LAN origins — **without modifying any shipped dsh code**.

## Features

| | |
| --- | --- |
| 🌐 **LAN access** | Rebind the Web GUI to `0.0.0.0` via an id-targeted config patch. No `--host` flag involved, so the built-in `0.0.0.0` guard never runs |
| 🛡️ **`crypto.randomUUID` polyfill** | Injects a tiny script into `index.html` so `/api` RPCs work on non-secure HTTP origins (the Web API is undefined there) |
| 🔓 **Remote privileged methods** | Settings / credentials / agent presets work from the LAN too (`allowRemotePrivileged`, default on) |
| 📦 **Install once, keep working** | Static bundle auto-mounts into the profile and loads at DSH startup, survives restarts |

## Install

### One-liner (recommended)

**Windows (PowerShell)**

```powershell
irm https://raw.githubusercontent.com/woyeshishen/dsh-lan-access/main/scripts/install.ps1 | iex
```

**macOS / Linux**

```sh
bash <(curl -fsSL https://raw.githubusercontent.com/woyeshishen/dsh-lan-access/main/scripts/install.sh)
```

### dsh plugin command

**From npm**

```sh
dsh plugin --profile web add @woyeshishen/dsh-lan-access
```

**From GitHub**

```sh
dsh plugin --profile web add github:woyeshishen/dsh-lan-access
```

After install, the plugin auto-mounts into the profile; restart DSH (or hot-reload) to activate.

## Notes

- The bind host is pinned to `0.0.0.0` by this plugin's patch; edit
  `cordis.patch.yml` if you need a different posture.
- `--port` still works (the patch keeps the `!!js` port expression).
- By default privileged `/api` methods (settings/credentials/agent presets)
  are reachable from trusted LAN hosts (`allowRemotePrivileged: true`); set
  `config: { allowRemotePrivileged: false }` on the `lan-access` row to
  restore loopback-only for them.
- Uninstall: `dsh plugin --profile web remove @woyeshishen/dsh-lan-access`
- This plugin intentionally exposes a remote-code-execution surface to the
  network — only use it on a trusted LAN.

## Development

```sh
npm install
npm run build     # tsc -> lib/
npm run check     # type-check only
npm run check:legacy   # cordis.patch.yml structure sanity check
```

## License

[Apache-2.0](./LICENSE)

Install

dsh plugin --profile web add github:woyeshishen/dsh-lan-access#2727fa7629b396ddefc758c9572f4d6e29c6d759

Profile: web

  • This package builds from source on install. pnpm will ask you to allow its build script — that is permission to run the package’s code on your machine, outside the agent sandbox. Only allow sources you trust.
Source