TecFancy/dsh-auth-gate
Login gate for the dsh web surface: password or shared-token authentication, session cookies, rate limiting, and a user-management CLI (dsh.bundle manifest since 0.4.1, one-command dsh plugin add mounting).
A login door for a public DeepSeek Harness web instance: every page, API call and WebSocket connection is checked; visitors without a valid session get a login page (or 401 for API/script requests). Two sign-in modes — per-admin username/password (recommended) or one shared token — plus optional TOTP two-factor (RFC 6238, off/optional/required). Safe by default: hashed passwords, rate-limited logins with temporary address locks, secure session cookies, and missing/broken config blocks access instead of silently opening the door. Includes a dsh-auth CLI for user management and a bundled configuration skill for deployment-side agents.
Install
dsh plugin --profile web add dsh-auth-gatedsh plugin --profile web add dsh-auth-gate (npm dsh-auth-gate 0.11.0, verified on npm 2026-08-30). Since 0.4.1 the package declares a dsh.bundle manifest, so the mount registers automatically. Then create an admin: pnpm --dir "$DSH_HOME/profiles/web" exec dsh-auth user add admin --password-stdin, switch mode to password via a config override in $DSH_HOME/cordis.patch.yml, and restart dsh.
Compatibility
DSH web profile; Node >= 22.19 and pnpm; dsh-plugin-framework conventions; optional dsh-auth-proxy for remote settings editing; MIT.
Details
- Repo: TecFancy/dsh-auth-gate
- Category: Development & Runtime
- Stars: 8
- Version: npm dsh-auth-gate 0.11.0
- Last push: 2026-08-30
- First seen: 2026-08-14
Recent updates
Full-surface login gate (pages + API + WebSocket); password or token modes; optional TOTP 2FA; rate limiting; dsh-auth CLI; bundled config skill; optional dsh-auth-proxy for remote config editing.
FAQ
- Does it protect WebSockets too?
- Yes — every page, API call and WebSocket connection is checked; script clients can pass Authorization: Bearer <token>.
- What happens if config is broken?
- The plugin blocks access instead of silently opening the door — fail-closed by design.
- Can I use TOTP?
- Yes — in password mode, users with a TOTP secret sign in with password plus a 6-digit authenticator code; configurable off/optional/required.
Alternatives
xbzbing/dsh-auth-gateway · TecFancy/dsh-mobile · omdsh-dev/dsh-security-audit