TecFancy/dsh-auth-gate

Login gate for the dsh web surface: password or shared-token authentication, session cookies, rate limiting, and a user-management CLI (dsh.bundle manifest since 0.4.1, one-command dsh plugin add mounting).

A login door for a public DeepSeek Harness web instance: every page, API call and WebSocket connection is checked; visitors without a valid session get a login page (or 401 for API/script requests). Two sign-in modes — per-admin username/password (recommended) or one shared token — plus optional TOTP two-factor (RFC 6238, off/optional/required). Safe by default: hashed passwords, rate-limited logins with temporary address locks, secure session cookies, and missing/broken config blocks access instead of silently opening the door. Includes a dsh-auth CLI for user management and a bundled configuration skill for deployment-side agents.

Development & Runtime ★ 8 updated 2026-08-30
View on GitHub ↗

Install

dsh plugin --profile web add dsh-auth-gate

dsh plugin --profile web add dsh-auth-gate (npm dsh-auth-gate 0.11.0, verified on npm 2026-08-30). Since 0.4.1 the package declares a dsh.bundle manifest, so the mount registers automatically. Then create an admin: pnpm --dir "$DSH_HOME/profiles/web" exec dsh-auth user add admin --password-stdin, switch mode to password via a config override in $DSH_HOME/cordis.patch.yml, and restart dsh.

Compatibility

DSH web profile; Node >= 22.19 and pnpm; dsh-plugin-framework conventions; optional dsh-auth-proxy for remote settings editing; MIT.

Details

Recent updates

Full-surface login gate (pages + API + WebSocket); password or token modes; optional TOTP 2FA; rate limiting; dsh-auth CLI; bundled config skill; optional dsh-auth-proxy for remote config editing.

FAQ

Does it protect WebSockets too?
Yes — every page, API call and WebSocket connection is checked; script clients can pass Authorization: Bearer <token>.
What happens if config is broken?
The plugin blocks access instead of silently opening the door — fail-closed by design.
Can I use TOTP?
Yes — in password mode, users with a TOTP secret sign in with password plus a 6-digit authenticator code; configurable off/optional/required.

Alternatives

xbzbing/dsh-auth-gateway · TecFancy/dsh-mobile · omdsh-dev/dsh-security-audit

More plugins in Development & Runtime

Browse more in Development & Runtime

Guides for Development & Runtime plugins