dsh-web-pass avatar

dsh-web-pass

DSH Web 密码门禁 – Cookie 认证 + 首次强制设密 + 登录失败锁定60s + 内置访问日志查看器。零依赖,原生集成设置页。

PluginSecurityStorageFileWeb search
Verification
L2 · Structured
Security
Low
Health
Active
Trust
Silver

What it doesAI

Adds a password gate to DSH web with cookie auth, first-run password setup, failure lockout, and privacy-safe IP-pseudonymized access logs.

  • Cookie session auth with 3-attempt lockout (401)
  • Forced password setup on first visit, min 8 chars
  • HMAC-pseudonymized IP logging with size-based rotation

AI-generated from the repo README — for reference only.

Installation

dsh plugin --profile web add github:linz919/dsh-web-pass

Install method: GitHub · not yet tested in container (L3+)

Compatibility

DSH VersionStatus
not statedDeclared — not tested

Requirements

  • • Node.js: not stated
  • • DSH: declared "not stated"
  • • External credentials: none detected

Security Report

Automated static scan, not manual review.

DSH.SO VETPASSEDe44705
Automated review · daily
PASSED

Vet static analysis found no suspicious behavior — verdict is clean.

0 critical·0 high·0 medium·100 score
plugin version0.2.0dsh manifest
scanned commite44705cfd74e2026-08-21
latest commite44705cfd74e
vet verdictclean · gitscore 100

Vet is an AST static scan (npm artifact or git source).

Disclaimer: automated static analysis, not a security guarantee. Always review what you install.

Risk details

No critical or warning findings.

Activity

Last commit 2026-08-21 · activity: Active

• Repo created: 2026-08-21

• Stars: ★ 0 · Forks: 0

• Health: Active — committed within last 30 days

Source

GitHub: github.com/linz919/dsh-web-pass

Was this page helpful?