slywalker2006/dsh-passwords
dsh-passwords: DeepSeek Harness login gateway - first-run setup, at-rest encryption, brute-force lockout, audi
dsh-passwords is a server-grade multi-tenant gateway for DeepSeek Harness that turns a local dsh instance into a remotely accessible, multi-user platform. DSH has no built-in login, permissions, or usage controls — anyone with the URL can use it. dsh-passwords adds a gateway in front: unauthenticated visitors see a login page; after sign-in, each account is subject to configured permission and quota enforcement. Features: login page + first-time setup (owner account created on first visit, subsequent visitors always go through login); automatic HTTPS (Let's Encrypt cert, zero config, auto-renewing, 80→443 redirect); session management (12-hour cookie sessions, survive browser restarts); multi-user (owner + unlimited subusers, all managed from a settings card — no SSH); per-subuser workspace allowlist (only assigned folders visible and openable, per-workspace session toggle); per-subuser hourly token and daily usage-time limits (requests rejected at cap); sandbox levels (read-only/workspace-write/full; escalation attempts above the assigned level are force-rejected); upload/git-download toggles; ban subusers; owner↔subuser in-app chat (tags: issue/PR/discussion/announcement/question; subuser messages default to DM to owner, only owner can broadcast); remote browser can use every dsh settings feature; UI follows dsh theme (dark/light).
Install
curl -fsSL https://raw.githubusercontent.com/slywalker2006/dsh-passwords/main/install.sh | bashFive install methods: (1) Linux/macOS direct install via curl one-liner (installs to /opt/dsh-passwords as root or $HOME/dsh-passwords as regular user; set DSH_PASSWORDS_DIR to change; if target dir exists the installer exits — delete old dir first); (2) clone and run install.sh manually; (3) npm global install (npm install -g dsh-passwords); (4) Windows: run install.bat; (5) Docker (docker compose up -d, initializes on first start). Host installs require Node.js 22.5+, a working dsh installation, and git; pnpm is installed automatically if missing. All host installers do the same automatically: install deps, build, generate random SETUP_KEY, register as dsh plugin, apply remote-settings patch. The existing .env is never overwritten on re-run. After install visit http://localhost (HTTP redirects to HTTPS automatically) to complete first-time owner account setup.
Compatibility
DeepSeek Harness web and headless profiles. Host: Node.js 22.5+, dsh, git. Docker: Docker Engine or Docker Desktop + DeepSeek API key (no Node.js needed on host). Automatic HTTPS via Let's Encrypt (ports 80/443; non-root users need sudo to bind 80/443). Remote-settings patch applied automatically: allows remote browsers to use dsh settings and includes a one-click 'Reload patch' fix for settings breakage after dsh upgrades. Multi-tenant: one owner account + unlimited subusers. Each subuser can have: workspace allowlist, hourly token limit, daily usage-time limit, sandbox level (read-only/workspace-write/full access), upload/git-download toggles. In-settings card for all account management — no SSH needed. Login sessions last 12 hours via cookie. Every login attempt (success and failure) is logged.
Details
- Repo: slywalker2006/dsh-passwords
- Category: Other
- Stars: 15
- Version: npm package dsh-passwords 2.6.1 (registry-verified 2026-08-23)
- Last push: 2026-08-17
- First seen: 2026-08-14
Recent updates
The current English README documents: five install methods (Linux/macOS curl, clone+script, npm global, Windows bat, Docker), Node.js 22.5+ requirement, first-time setup flow, HTTPS automation, 12-hour cookie sessions, multi-user model (owner + subusers), workspace allowlist, hourly token and daily usage-time limits, sandbox levels with force-reject on escalation, upload/git-download toggles, ban, owner↔subuser chat with tagging, remote-settings patch (and one-click reload fix), login audit log.
FAQ
- What does the gateway do on first access?
- On first visit you create the owner account (username + password); afterwards every visitor — including you — goes through the login page before reaching dsh.
- Do I need a domain or external DNS?
- No — automatic HTTPS is handled at install with Let's Encrypt; port 80 redirects to 443 automatically. Non-root users need sudo to bind low ports.
- Can subusers change their own password?
- Yes — subusers can change their own username and password from the settings card; they cannot manage other accounts. The owner manages all subusers.
Alternatives
lbwnb666-ai/DeepSeekHarnessRemoteGateway · omdsh-dev/dsh-advisor · slywalker2006/dsh-passwords