dsh-lan-gate
安全与治理 活跃维护

dsh-lan-gate

maxesisnclaw/dsh-lan-gate

支持密码验证与CIDR网段规则双重校验,为局域网Web服务提供轻量化访问门禁,规则配置简单,可快速拦截未授权用户与非法网段的访问请求。

0
Stars 标星
0
Forks 分支
0
Watchers 关注
0
Open Issues
JavaScript
主要语言
MIT
开源协议
27 KB
仓库大小
1 个月前
最后推送
一键安装扩展 / 插件指令
dsh plugin --profile web add github:maxesisnclaw/dsh-lan-gate
git clone https://github.com/maxesisnclaw/dsh-lan-gate.git
git clone git@github.com:maxesisnclaw/dsh-lan-gate.git
README.md main

dsh-lan-gate

English | 中文

Password gate + CIDR allowlist + proxy-header deny for DeepSeek Harness web.

dsh web --host 0.0.0.0 is rejected by the CLI. This bundle sets webserver.host to 0.0.0.0 through the official composition layer, then requires a password before the UI or /api is reachable from the LAN.

Install

dsh plugin --profile web add dsh-lan-gate

Or from GitHub:

dsh plugin --profile web add github:maxesisnclaw/dsh-lan-gate

Then open http://127.0.0.1:3080/dsh-lan-full/login and set a password (loopback only). After that, LAN clients get the login page.

Settings → LAN access / LAN 访问 edits CIDRs, proxy-header policy, and the password. The settings section and login page follow dsh's official zh/en locale.

What it does

Control Default
Listen on all interfaces yes (bundle patch)
Password unset until you set it from loopback
Inbound IPv4 CIDRs 10.0.0.0/8, 172.16.0.0/12, 192.168.0.0/16
Reject X-Forwarded-* / Forwarded / Via yes
Loopback bypasses password yes (recovery)

Policy file: $DSH_HOME/lan-gate.json (mode 0600). The password is stored as a scrypt verifier, never as plaintext. Session tokens are random 32-byte values; only their SHA-256 is kept in memory.

Residual risk

This is not a TLS terminator. On plain HTTP a LAN observer can still sniff the password and cookie. Do not put this on the public internet. Do not sit it behind a reverse proxy that adds forwarding headers — those requests are rejected on purpose.

See SECURITY.md.

License

MIT