Yuuz12/dsh-webui-auth
WebUI identity authentication: HTTP/transport layer forced login (resource, plug-in bundle, /api, WebSocket four-layer protection), server session + HttpOnly Cookie
A persistent WebUI authentication plugin for DeepSeek Harness: configure an account name and password in Settings, and the plugin adds a login gate to the DSH web UI at the transport layer — all HTTP resources, plugin APIs, and WebSocket connections require a valid session before being served. Includes rate-limiting on failed login attempts and a session-expiry setting. Intended for deployments where DSH is exposed on a non-loopback address and basic access control is needed without running a full reverse-proxy.
Install
dsh plugin --profile web add dsh-webui-authdsh plugin --profile web add dsh-webui-auth (npm dsh-webui-auth 0.3.2, repo Yuuz12/dsh-webui-auth, package.json name=dsh-webui-auth v0.3.2 verified 2026-08-30).
Compatibility
DSH web profile; HTTP/transport layer forced login (intercepts resources and plugin endpoints); rate-limiting on failed attempts; MIT.
Details
- Repo: Yuuz12/dsh-webui-auth
- Category: Web UI Enhancements
- Stars: 7
- Version: npm dsh-webui-auth 0.3.2
- Last push: 2026-09-16
- First seen: 2026-08-14
Recent updates
HTTP/transport layer login gate (account+password in Settings); intercepts resources + plugin endpoints + WebSockets; rate-limiting; session expiry.
FAQ
- How is this different from dsh-auth-gate?
- dsh-auth-gate (TecFancy) offers password/token modes plus optional TOTP 2FA and a separate dsh-auth CLI; dsh-webui-auth focuses on a simpler Settings-page credential setup at the HTTP/transport layer — both achieve access control but differ in feature depth and configuration approach.
- Does it protect WebSocket connections too?
- Yes — authentication is enforced at the transport layer before the WebSocket handshake, so unauthenticated clients cannot establish a DSH session connection.
- Can I use this if DSH is behind a reverse proxy?
- Yes, though you may want to use the reverse proxy's own auth (nginx basic auth, Cloudflare Access, etc.) instead for stronger security; this plugin is most useful for quick deployment protection without additional infrastructure.
Alternatives
TecFancy/dsh-auth-gate · xbzbing/dsh-auth-gateway · TecFancy/dsh-mobile