@softspark/dsh-file-preview
Read-only file preview inside a DeepSeek Harness conversation. Click a file the agent produced or mentioned and it opens in the browser, instead of launching a desktop application.
Works on the published harness. No patch, no fork, no modified checkout.
What's New in v2.0.0
- DSH
0.1.2-rc.1 support through its Session Remote opener and immutable host event snapshots.
- Enforced 70% coverage, filesystem authorization integration tests, and browser registration tests.
- Complete post-release SOP and published browser TypeScript declarations.
Version 2 requires DSH 0.1.2-rc.1. Keep plugin 1.0.0 when using DSH 0.1.1-rc.2.
Contents
Why
Without it, opening a file from a conversation hands the path to the host operating system. That is the wrong gesture when the harness runs on a remote machine, in a container, or when the file is a diff you want to glance at without leaving the page.
Requirements
- Node.js 22.19.0 or newer
- DeepSeek Harness
0.1.2-rc.1
pnpm for the profile plugin manager
Install
dsh plugin --profile web add @softspark/dsh-file-preview --save-exact
Restart DSH. The package registers both of its rows itself.
What it previews
| Kind | Formats | Bound |
|---|
| Text and code | .txt .md .json .yaml .toml .csv .ts .js .py .go .rs .sql and more | 1 MiB |
| Markup | .html .svg, sanitised to an allowlist | 1 MiB |
| Images | .png .jpg .gif .webp | 8 MiB |
| Documents | .pdf | 8 MiB |
Anything else reaches the harness's own opener untouched, exactly as before the plugin was installed.
How it claims a click
Every conversation file-open in DSH 0.1.2 reaches remote.session.openWorkspacePath({ path }). The browser half wraps its getter while preserving the native request, cancellation signal, and caller context. Removing the package restores the original descriptor.
If a future harness stops exposing that method, the plugin refuses to mount rather than silently swallowing clicks.
Security
A preview must not become an arbitrary host-file read. Authorization is computed on the host from session facts alone: a file is readable when it sits inside the addressed session's workspace, or when that same session produced it through a successful write or edit. Failures never carry file bytes, and both refusal grounds return the same code so a rejection cannot be used to probe for a file's existence.
Full model in kb/reference/security.md and SECURITY.md.
Documentation
Contributing
See CONTRIBUTING. pnpm run verify is the gate.
License
Apache-2.0. See LICENSE and NOTICE.
Changelog
See CHANGELOG.md for the full release history.