Forwards a local dsh web UI to the public internet under a *.ds.hn subdomain (or your own self-hosted relay), gated by a login, with optional end-to-end encryption (PBKDF2 to AES-256-GCM).
Install
# from npm (prebuilt)
dsh plugin --profile web add @dshn/agent
# from a prebuilt release tarball
dsh plugin --profile web add "https://github.com/jsdvjx/dshn/releases/latest/download/dshn.tgz"
# from GitHub (first run asks for allowBuilds approval — follow the hint, retry)
dsh plugin --profile web add github:jsdvjx/dshn#path:/packages/agent
Any plugin you install runs third-party code with your own permissions — it can read your files, use your credentials, and reach the network, and tool approvals don’t sandbox it. GitHub-sourced plugins also run build scripts at install time — pnpm blocks those until you allow them, so an install can stop with ERR_PNPM_GIT_DEP_PREPARE_NOT_ALLOWED or ERR_PNPM_IGNORED_BUILDS; dsh prints the exact key to add under allowBuilds in your profile’s pnpm-workspace.yaml, and the install works on the next run. Allowing a build is a trust decision: only install sources you trust, and pin a commit (github:owner/repo#sha).
README
The dsh plugin half of dshn. It opens one outbound WebSocket
to the relay, claims a subdomain with the (subdomain, password) the user typed in
the setup dialog, and replays whatever the relay forwards against the local dsh
web server — HTTP over node:http, dsh's own /api/events.* downlink sockets
over a tunnelled ws client.
Two halves:
- Host (
src/index.ts→lib/index.js): the tunnel client, the replay engine, the reconnect/heartbeat loop, credential persistence, and the/dshn/status·/dshn/configure·/dshn/disconnectroutes. - Browser (
client.js, hand-authored factory format): ashell.overlaypill that opens the setup dialog when unconfigured (subdomain + password), or the live status + public URL when connected.
Why no trustedHosts patch
The agent rewrites each forwarded request's Host/Origin to the local loopback
authority before replaying it to dsh. dsh's /api browser-trust fence then
accepts it as a loopback, same-origin request — for any subdomain, with no
composition-time trusted-host entry. That is what lets the subdomain be chosen at
runtime in the dialog; access is gated by the relay's login instead of the fence.
Config
Credentials (subdomain + password) are not configured here — the user sets
them in the dialog (POST /dshn/configure, loopback-only) and they persist to
DSHN_STATE. Only infrastructure is env-configured:
| env | meaning | default |
|---|---|---|
DSHN_RELAY_HOST |
host the tunnel dials | relay.ds.hn |
DSHN_ORIGIN_CA |
PEM cert to pin when dialing a direct grey-cloud origin | — |
DSHN_STATE |
file the chosen credentials persist to | ~/.dshn-agent.json |
DSHN_LOCAL_PORT |
local dsh port to replay against | the web server's port |
DSHN_ENABLED |
0 loads the plugin inert |
1 |
Links
More in this category
zhu1090093659/dsh-web#packages/dsh-remote-web-ui★ 8370
Remote control of a dsh web workspace from phone or PC: QR-code pairing through a token-gated channel, SSE real-time sync, and separate mobile and full desktop GUI modes.
zhu1090093659/dsh-web#packages/dsh-ssh★ 8370
SSH ops panel for DSH: web terminal, SFTP transfer with progress, local port forwarding, and one-command cluster execution across hosts; agents share the same host config.
saya-ch/dsh-mobile★ 371
Access DeepSeek Harness from the Android app or a mobile browser with secure LAN and remote connections, persistent device pairing, and a customizable mobile interface.
ZSeven-W/dsh-ios★ 312
A live iOS Simulator or USB-connected iPhone inside the conversation: 22 agent tools for booting, building, driving the UI by accessibility identity or OCR text, list-row actions and SwiftUI preview hot reload, plus a streaming sidebar panel you can tap and drag on.
liguobao/ds-harness-remote★ 266
Multi-device remote access for DeepSeek Harness: continue an active session from your phone, tablet, browser, or another computer over an end-to-end encrypted channel (Noise IK + adaptive relay/WebRTC transport), with device authorization, ApiProxy-only remote capabilities, and read-only file preview via dsh-file-viewer — no shell, remote desktop, or write access.
wenbin-wb/dsh-bridge★ 184
Remote and mobile access for DeepSeek Harness: provides LAN QR code connection, Cloudflare/custom tunnels, WeChat, QQ, Feishu, Telegram bot integration, and security authentication.
Community comments
Comments are public GitHub Discussions. Loading them connects to GitHub and Giscus; a GitHub account is required to post.