把本地 dsh 网页通过带登录门禁的中继转发到公网 *.ds.hn 子域名(也可自托管到自己的域名),支持可选的端到端加密(PBKDF2 到 AES-256-GCM)。
安装
# npm 包(预构建)
dsh plugin --profile web add @dshn/agent
# Release 预构建包
dsh plugin --profile web add "https://github.com/jsdvjx/dshn/releases/latest/download/dshn.tgz"
# GitHub 源码(首次需按提示配置 allowBuilds 构建授权后重试)
dsh plugin --profile web add github:jsdvjx/dshn#path:/packages/agent
装任何插件都等于在你的机器上跑第三方代码,权限和你本人一样大——能读你的文件、用你的凭据、访问网络,工具审批管不到它。GitHub 来源的插件还会在安装时执行构建脚本——pnpm 默认拦截,所以安装可能停在 ERR_PNPM_GIT_DEP_PREPARE_NOT_ALLOWED 或 ERR_PNPM_IGNORED_BUILDS;dsh 会打印出需要添加的确切键名,把它加进该 profile 的 pnpm-workspace.yaml 的 allowBuilds 下,重跑一次即可装上。放行构建本身就是一次信任判断:请只安装可信来源,并尽量锁定 commit(github:owner/repo#sha)。
README
该插件的 README 只有英文版本。
The dsh plugin half of dshn. It opens one outbound WebSocket
to the relay, claims a subdomain with the (subdomain, password) the user typed in
the setup dialog, and replays whatever the relay forwards against the local dsh
web server — HTTP over node:http, dsh's own /api/events.* downlink sockets
over a tunnelled ws client.
Two halves:
- Host (
src/index.ts→lib/index.js): the tunnel client, the replay engine, the reconnect/heartbeat loop, credential persistence, and the/dshn/status·/dshn/configure·/dshn/disconnectroutes. - Browser (
client.js, hand-authored factory format): ashell.overlaypill that opens the setup dialog when unconfigured (subdomain + password), or the live status + public URL when connected.
Why no trustedHosts patch
The agent rewrites each forwarded request's Host/Origin to the local loopback
authority before replaying it to dsh. dsh's /api browser-trust fence then
accepts it as a loopback, same-origin request — for any subdomain, with no
composition-time trusted-host entry. That is what lets the subdomain be chosen at
runtime in the dialog; access is gated by the relay's login instead of the fence.
Config
Credentials (subdomain + password) are not configured here — the user sets
them in the dialog (POST /dshn/configure, loopback-only) and they persist to
DSHN_STATE. Only infrastructure is env-configured:
| env | meaning | default |
|---|---|---|
DSHN_RELAY_HOST |
host the tunnel dials | relay.ds.hn |
DSHN_ORIGIN_CA |
PEM cert to pin when dialing a direct grey-cloud origin | — |
DSHN_STATE |
file the chosen credentials persist to | ~/.dshn-agent.json |
DSHN_LOCAL_PORT |
local dsh port to replay against | the web server's port |
DSHN_ENABLED |
0 loads the plugin inert |
1 |
链接
同类插件
zhu1090093659/dsh-web#packages/dsh-remote-web-ui★ 8370
手机/PC 远程操控 dsh web 工作区:扫码配对、令牌门控通道、SSE 实时同步,提供移动端与完整桌面 GUI 两种远程形态。
zhu1090093659/dsh-web#packages/dsh-ssh★ 8370
SSH 远程运维面板:Web 终端、SFTP 传输、本地端口转发与一条命令并发集群执行,Agent 与面板共用同一份主机配置。
saya-ch/dsh-mobile★ 371
通过 Android App 或手机浏览器访问 DeepSeek Harness,支持安全局域网连接、远程访问、持久设备配对和可自定义移动界面。
ZSeven-W/dsh-ios★ 312
在对话里直接操作 iOS 模拟器或 USB 连接的 iPhone:22 个 Agent 工具用于启动、构建、按无障碍标识或 OCR 文本驱动 UI、列表行操作与 SwiftUI 预览热重载,并附带可点击拖拽的流式侧边栏面板。
liguobao/ds-harness-remote★ 266
DeepSeek Harness 多端远程访问:从手机、平板、浏览器或另一台电脑继续进行中的会话,端到端加密通道(Noise IK + 自适应 Relay/WebRTC 传输),设备授权管理;远程端仅开放 ApiProxy 能力,支持 dsh-file-viewer 只读文件预览,不提供 Shell、远程桌面或写入权限。
wenbin-wb/dsh-bridge★ 184
DeepSeek Harness 远程与移动端接入插件:提供局域网扫码直连、Cloudflare 与自建公网隧道,以及微信、QQ、飞书、Telegram 机器人交互,内置安全认证与访问控制。
社区评论
评论公开保存在 GitHub Discussions。加载评论会连接 GitHub 和 Giscus;发表内容需要 GitHub 账号。