Upload arbitrary local files from the Web composer, show pending cards, and manage stored files in Settings.
Install
# from GitHub (first run asks for allowBuilds approval — follow the hint, retry)
dsh plugin --profile web add github:l541402398/dsh-file-uploads
Any plugin you install runs third-party code with your own permissions — it can read your files, use your credentials, and reach the network, and tool approvals don’t sandbox it. GitHub-sourced plugins also run build scripts at install time — pnpm blocks those until you allow them, so an install can stop with ERR_PNPM_GIT_DEP_PREPARE_NOT_ALLOWED or ERR_PNPM_IGNORED_BUILDS; dsh prints the exact key to add under allowBuilds in your profile’s pnpm-workspace.yaml, and the install works on the next run. Allowing a build is a trust decision: only install sources you trust, and pin a commit (github:owner/repo#sha).
README
English | 简体中文
Upload arbitrary local files from the DeepSeek Harness Web composer, attach their container paths to prompts, and manage stored uploads from Settings.
Features
- Adds a Files button beside the existing composer controls.
- Accepts multiple arbitrary local files, not only images.
- Shows pending files as image-like cards above the composer.
- Keeps the text editor clean: no visible path or generated description is inserted into the draft.
- Serializes each hidden file reference into a model-readable absolute path only when the message is submitted.
- Clears pending cards after submission and restores them when submission fails.
- Stores every upload in one fixed directory,
$DSH_HOME/uploadsby default. - Lists uploaded files in Settings → Uploaded files, with download and delete actions.
- Prevents overwrites by publishing duplicates as
name (1).ext,name (2).ext, and so on. - Enforces per-file and total-directory quotas.
Compatibility
- DeepSeek Harness
0.1.0-rc.6 - Web profile
- Node.js 22 or newer
Harness currently transports native attachments as raster images only. This plugin intentionally uses the arbitrary-file path supported by the agent environment: it stores the file inside the Harness host/container and adds that path to the submitted text through the built-in input-reference serializer.
Install
Install the tagged GitHub release into the Web profile:
dsh plugin --profile web add "github:l541402398/dsh-file-uploads#v1.0.0"
Restart the running Web profile after installation, then refresh the browser page.
To install the latest development branch instead:
dsh plugin --profile web add "github:l541402398/dsh-file-uploads#main"
To remove it:
dsh plugin --profile web remove dsh-file-uploads
Use
Open a conversation in the Harness Web GUI.
Select Files in the composer toolbar.
Choose one or more local files.
Review or remove the pending cards above the composer.
Add any normal prompt text you want, or leave the editor empty.
Submit the message. The model receives a line such as:
上传文件:`/path/to/.dsh/uploads/report.pdf`
The generated line is never shown in the editor before submission. The stored path refers to the filesystem visible to the Harness host; in a Docker deployment, this is the path inside the container.
Settings
The plugin adds an Uploaded files section to Settings. It displays:
- the fixed storage directory;
- per-file and total-directory limits;
- current storage usage;
- file name, size, modification time, and absolute path;
- download and delete actions.
Files persist until they are deleted manually.
Configuration
The plugin works without configuration. These environment variables override its defaults:
| Variable | Default | Purpose |
|---|---|---|
DSH_UPLOAD_DIR |
$DSH_HOME/uploads |
Absolute upload directory. |
DSH_UPLOAD_MAX_BYTES |
104857600 |
Maximum bytes per file (100 MiB). |
DSH_UPLOAD_TOTAL_MAX_BYTES |
1073741824 |
Maximum total bytes in the directory (1 GiB). |
Example Docker Compose fragment:
services:
dsh:
environment:
DSH_UPLOAD_DIR: /data/dsh/uploads
DSH_UPLOAD_MAX_BYTES: 104857600
DSH_UPLOAD_TOTAL_MAX_BYTES: 1073741824
volumes:
- ./dsh-data:/data/dsh
Security model
- List, upload, download, and delete routes use the same loopback/trusted-host and Origin checks as the built-in Harness Web API.
- Cross-site browser requests are rejected.
- File names are normalized and stripped of path components and control characters.
- Downloads and deletions accept only regular files in the configured directory and do not follow symbolic links.
- Uploads are written to private temporary files, synced, and atomically published without overwriting existing files.
- Interrupted
.upload-*temporary files are removed when the plugin starts. - Unexpected server errors are logged without returning internal paths to the browser.
This trust fence is not a user-account authentication system. If the Harness Web GUI is exposed to other users or the public Internet, protect the whole deployment with an authenticated reverse proxy and configure Harness trusted hosts correctly.
Development
Run the checks:
npm test
npm run check
The package is a persistent dual-face Cordis bundle:
index.js— Host HTTP routes, storage, quotas, and trust checks.client.js— composer button, pending-file rail, hidden reference codec, and Settings UI.cordis.patch.yml— installabledsh.bundlecomposition row.test/upload-manager.test.js— Host storage and security regression tests.
See CONTRIBUTING.md for local-link development instructions.
License
Links
More in this category
zhu1090093659/dsh-web#packages/dsh-task-board★ 8076
Task board for the dsh web GUI: a sidebar multi-column kanban whose cards run in real DSH agent sessions and can also be scheduled with cron expressions, executed host-side even with the browser closed.
zhu1090093659/dsh-web#packages/dsh-web-all★ 8076
Plugin and skin collection for the DSH Web UI: task board, Git graph, right-side panel, remote mobile UI, pet, live token stats, and a skin center.
omdsh-dev/DSH-better-sidebar★ 3828
Full sidebar workbench with file rendering and editing, terminal, Git, and subagents; third-party plugins can register new tabs.
ccch1mneyyy/dsh-TUI★ 3661
Claude Code-style full-screen terminal UI: pixel-whale header, live status line, and streaming thought expansion.
MeteorNOX/DeepSeek-Balance-Whale-Widget★ 3277
A fixed-corner whale widget for the DSH web GUI — balance, today's usage and per-turn cost with peak/off-peak pricing, editable balance-alert and daily-budget bubbles, a module-based custom bubble queue with A/B weighted choices and random lines or images, 30+ vendor templates (OpenAI, OpenRouter, Kimi, SiliconFlow, Ark, Zhipu, MiniMax and more) with per-model balance and subscription quota, plus task-end sound, imported audio, custom roles and a resource manager. Local-only, no telemetry.
Devin-AXIS/deepseek-design#deepseek-idesign★ 1628
Visual design studio for websites, app prototypes, posters, cards, reports, and magazines, with templates, direct element editing, selection-aware AI draft handoff, and export.
Community comments
Comments are public GitHub Discussions. Loading them connects to GitHub and Giscus; a GitHub account is required to post.