What it doesAI
Adds JWT login wall and per-user workspace/session visibility to DeepSeek Harness web GUI.
- JWT login wall with HttpOnly cookie
- Per-user workspace and session visibility filtering
- User management: add, disable, delete, change password
AI-generated from the repo README — for reference only.
Installation
dsh plugin --profile web add dsh-multi-userInstall method: npm · not yet tested in container (L3+)
Compatibility
| DSH Version | Status |
|---|---|
| not stated | Declared — not tested |
Requirements
- • Node.js: not stated
- • DSH: declared "not stated"
- • External credentials: none detected
Security Report
Automated static scan, not manual review.
No critical findings, but warning-level issues were detected (file writes, remote imports, base64 decoding, downloads).
0.1.0dsh manifestc750bed8df2d2026-08-20c750bed8df2dThe scan result is valid for the scanned commit. New commits within 7 days are tolerated (the rating still counts); after 7 days without a rescan the badge shows outdated.
Disclaimer: automated static analysis, not a security guarantee. Always review what you install.
vet verdict: vet: clean · score 100
- R2 · info [likely] — require()(客户端加载器 factory 形参注入,DSH bundle 标准写法)
- R2 · info [likely] — require()(客户端加载器 factory 形参注入,DSH bundle 标准写法)
- R2 · info [likely] — require()(客户端加载器 factory 形参注入,DSH bundle 标准写法)
- R3 · info [certain] — 只读 process 成员(能力触达面):process.pid
- R3 · info [certain] — 只读 process 成员(能力触达面):process.platform
vet is advisory and does not change dsh’s four-tier level.
• Static heuristic scan: done (10 files)
• Dependency vulnerabilities: requires deep audit (L3+)
• Permission sandboxing: requires runtime testing (L4+)
High-risk findings · 4 / 4
- warningFilesystem write operationslib/index.js:100fs.writeFileSync(tmp, JSON.stringify(value, null, 2) + "\n", { mode: 384 });
- warningFilesystem write operationssrc/jwt.ts:42fs.writeFileSync(secretPath, secret, { mode: 0o600 });
- warningFilesystem write operationssrc/jwt.ts:44fs.chmodSync(secretPath, 0o600);
- warningFilesystem write operationssrc/store.ts:70fs.writeFileSync(tmp, JSON.stringify(value, null, 2) + '\n', { mode: 0o600 });
Heuristic static scan — may produce false positives. Review the source yourself before trusting.
Activity
Last commit 2026-08-20 · activity: Active
• Repo created: 2026-08-20
• Stars: ★ 0 · Forks: 0
• Health: Active — committed within last 30 days
