Dynamically trusts every Host header that actually arrives and flips the default web binding to 0.0.0.0: wildcard or unenumerable entry domains work without editing the start command, the authentication layer is untouched, and hosts are evicted by LRU beyond a capacity cap.
Install
# from npm (prebuilt)
dsh plugin --profile web add @mzzsfy/dsh-auto-trust-all
# from GitHub (first run asks for allowBuilds approval — follow the hint, retry)
dsh plugin --profile web add github:mzzsfy/dsh-plugin#path:/packages/dsh-auto-trust-all
Any plugin you install runs third-party code with your own permissions — it can read your files, use your credentials, and reach the network, and tool approvals don’t sandbox it. GitHub-sourced plugins also run build scripts at install time — pnpm blocks those until you allow them, so an install can stop with ERR_PNPM_GIT_DEP_PREPARE_NOT_ALLOWED or ERR_PNPM_IGNORED_BUILDS; dsh prints the exact key to add under allowBuilds in your profile’s pnpm-workspace.yaml, and the install works on the next run. Allowing a build is a trust decision: only install sources you trust, and pin a commit (github:owner/repo#sha).
README
This plugin publishes its README in Chinese only.
DeepSeek Harness web 入口插件:动态信任所有实际到达的 Host,并将 web 默认绑定翻转为全部网卡——dsh web 零参数启动等效 dsh web --host 0.0.0.0 --trusted-host=<任何实际到达的 host>。
功能
- 动态信任:包装 webServer 全部路由(exact / prefix / upgrade / fallback,含激活前已注册与后续新注册),请求到达即提取 Host 头(与官方信任闸门同构的 WHATWG 解析:小写、去端口、IPv6 保留方括号),去重后双写
webRuntime.trustedHosts与connection服务实例的trustedHosts快照数组(官方闸门读后者;两数组是装配期克隆的不同对象,缺一则动态域名对/api闸门不可见),闸门每请求实时读数组,无需重启。泛域名(*.example.com)等无法枚举的入口不再需要改启动命令。 - LRU 容量:注册域名容量
maxHosts默认 100(上界 4096),超出按最久未访问淘汰,活跃入口不易被挤出;淘汰同步作用于webRuntime.trustedHosts与 fence 两个数组,内存总量恒定有界。官方初始条目(部署派生的局域网 IP 等)与 loopback(localhost/[::1]/127.x——官方闸门对其恒放行,登记零增益;*.localhost官方不放行,照常登记)不参与记账。 - console 输出:启动时输出一行状态横幅(绑定、容量、既有信任条目);此后每次注册输出
auto-trust-all: registered host <域名>、每次淘汰输出auto-trust-all: evicted host <域名>,直接 grep dsh console 即可做入口审计。 - 默认绑定翻转:bundle patch 覆盖官方 webserver 行的 host 默认值为
0.0.0.0;显式--host 127.0.0.1仍生效(表达式读 webStartup 服务,只翻默认值)。 - 认证层不动:只影响官方 Host/Origin 信任闸门(官方文档明言"绝不建立身份"的可达性闸门);原生浏览器 cookie 认证与 dsh-web-startup-auth 会话闸门原样保留,安全增量趋近于零。
- 干净降级:冷启动时
webRuntime尚未就绪属预期,插件挂服务激活事件自动延迟启用;等待提示延后——超过 15 秒仍未就绪才输出webRuntime 未就绪等待行,正常启动不产生该行;官方 web 面形态变化(路由表缺 Map 形态或注册方法缺失)时告警后停用,不产生启动 pending、不影响 dsh 启动与其余功能;connection服务缺失时 fence 双写静默降级(仅webRuntime侧生效,不影响注册主路径)。 - 卸载即撤销:卸载时置空共享载体(带身份校验:新代已接管则跳过撤销与置空,防旧代误删新一代记账中的条目)并从两个数组移除本代注册的全部条目,信任放行随插件移除停止。
配置(无 GUI)
唯一配置项 maxHosts(注册域名容量,自然数,默认 100)。走 cordis 行级配置,在 profile 的 cordis.patch.yml(或 ~/.dsh/cordis.patch.yml)追加覆盖行,行级配置变更经热重载换代即按新容量生效,无需重启:
- id: auto-trust-all
config:
maxHosts: 200
容量按激活代记账:换代(热重载/行级配置变更)时若新一代先接管,旧代卸载跳过撤销,遗留条目视同官方条目留存、由新一代按需重新记账,重启 dsh web 则动态条目全部归零;新一代尚未接管即卸载(真卸载)时,本代注册条目从两个数组移除。
安装
任何 dsh plugin add(开发或发布安装)都会把 node_modules 里的既有 junction 重建为实体目录,装完必须重跑 node scripts/dev-link.mjs all 恢复工作副本挂载,否则改仓库源码不生效。
发布版安装:
dsh plugin --profile web add @mzzsfy/dsh-auto-trust-all
开发安装(仓库工作副本直挂,不经 npm 发布):
node scripts/dev-link.mjs dsh-auto-trust-all # 仓库根执行:归一 profile 依赖行 + 挂 junction
bundle patch 经 dev-link 维护的 hmr 覆盖行保存约 1 秒热重载;规约与全仓归一见 node scripts/dev-link.mjs all。
patch 覆盖官方 webserver 行的 config 是整体替换语义,本包已完整镜像官方全部键;该镜像由 test/patch.test.mjs 快照锁定——但该测试读不到官方安装目录,不能自动检出上游增删键。dsh 升级后请用 dsh web --dump-default-config 对照官方 webserver 行核对键集,发现新键需同步 cordis.patch.yml。
与其他插件的关系
- dsh-web-startup-auth:完全共存。本插件不提供任何 cordis 服务,零服务冲突;两者都会遮蔽 webServer 注册方法包装路由,委托链在任意激活顺序下保持正确(会话检查与 Host 注册同时生效)。未认证请求至多完成 Host 登记(纯观察),首个拦截点始终是会话闸门。配合语义:startup-auth 的账号会话(
dsh_sid,30 天)+ 官方 cookie 铸币跳(会话通过但缺官方 cookie 的 GET 由它代签并 303 回跳)替代了?token=的 per-process 分发——重启 dsh 后浏览器免输 token;本插件则让泛域名新入口免改启动命令即可达。 - dream-skin 等同构自守卫插件:同样实时读
webRuntime.trustedHosts,本插件的注册对它们同步生效。
安全边界
放行的是可达性闸门:攻击者可让任意域名指向本服务并到达登录页(受 startup-auth IP 限速约束),拿不到任何数据。闸门内建的 sec-fetch-site: cross-site 拒绝与 Origin 同源检查独立于信任清单,不受本插件影响。泛解析范围控制与防火墙仍是运维责任。
原生 cookie 会话按 主机:端口 绑定,每个新入口(各子域、各内网 IP 形态)都需要各自登录一次——这是 dsh 原生行为,与本插件无关。
被 LRU 淘汰的域名对 web 入口在重启前不可达:信任闸门在请求进入路由前拒绝已不信任的 Host,请求到不了注册钩子,无法自我恢复;LRU(最久未访问先淘汰)语义使活跃入口被低频新入口挤出的概率远低于按注册先后淘汰。
已知行为与边界
- 卸载后,遮蔽的注册方法与路由包装标记滞留:其后新注册的路由仍会过一层透传包装(每请求一次 no-op 载体调用,代价微小),属防卸载期路由半包装的既定取舍,进程存续期不可逆。
- 激活后对
webServer.fallback实例字段的直接赋值不经包装,该 handler 的请求不注册 Host(本插件只拦注册方法与激活时点已存在的路由)。 - 未认证请求至多完成 Host 登记(纯观察),首个拦截点始终是会话闸门;多样化 Host 流量下 registered / evicted 日志逐条输出,可作入口审计也可能成为日志噪声来源。
- 第三方直接收缩信任数组时,已记账条目的重访不会自动回填(命中记账即短路,回填由新域名注册触发);被 LRU 淘汰或换代遗留的条目留存至 dsh web 重启。
开发
cd packages/dsh-auto-trust-all
node --test "test/*.test.mjs"
宿主半区改动经 dev-link junction 热重载,保存约 1 秒重载;冒烟验证:dsh web 启动后以非常见 Host 头请求任一路由,响应正常且 console 出现 registered 前缀日志。
dsh 版本兼容
三版本(0.1.2-rc.1 / 0.1.5-rc.2 / 0.1.6-alpha.1)全部通过:0.0.0.0 动态信任、伪造 Host 200、LAN 访问、激活 live、diagnostics 0 findings。
Links
More in this category
zhu1090093659/dsh-web-ui#packages/dsh-ssh★ 7725
SSH ops panel for DSH: web terminal, SFTP transfer with progress, local port forwarding, and one-command cluster execution across hosts; agents share the same host config.
zhu1090093659/dsh-web#packages/dsh-remote-web-ui★ 7725
Remote control of a dsh web workspace from phone or PC: QR-code pairing through a token-gated channel, SSE real-time sync, and separate mobile and full desktop GUI modes.
ZSeven-W/dsh-ios★ 295
A live iOS Simulator or USB-connected iPhone inside the conversation: 22 agent tools for booting, building, driving the UI by accessibility identity or OCR text, list-row actions and SwiftUI preview hot reload, plus a streaming sidebar panel you can tap and drag on.
saya-ch/dsh-mobile★ 273
Access DeepSeek Harness from the Android app or a mobile browser with secure LAN and remote connections, persistent device pairing, and a customizable mobile interface.
liguobao/deepseek-harness-remote★ 203
Multi-device remote access for DeepSeek Harness: continue an active session from your phone, tablet, browser, or another computer over an end-to-end encrypted channel (Noise IK + adaptive relay/WebRTC transport), with device authorization, ApiProxy-only remote capabilities, and read-only file preview via dsh-file-viewer — no shell, remote desktop, or write access.
wenbin-wb/dsh-bridge★ 166
Remote and mobile access for DeepSeek Harness: provides LAN QR code connection, Cloudflare/custom tunnels, WeChat, QQ, Feishu, Telegram bot integration, and security authentication.
Community comments
Comments are public GitHub Discussions. Loading them connects to GitHub and Giscus; a GitHub account is required to post.