DeepSeek Harness Plugin Hub

发布与管理完整 Harness Profiles,发现适合你的插件。

探索

插件目录环境预设文档中心动态

社区

发布插件联系我们报告问题

相关链接

Plugin Hub GitHubDeepSeek Harness 官方项目系统状态隐私说明
© 2026 DeepSeek Harness Plugin HubPowered byPaxTech

独立、非官方社区项目,与 DeepSeek 官方无隶属、授权或背书关系。

Secure Context Fix — DeepSeek Harness 插件(DSH Plugin)
DeepSeek Harness Plugin Hub
ProfilesPlugins分类动态文档登录管理 Profiles
ProfilesPlugins分类动态文档登录
← Plugins
S

dsh-secure-context-fix

Secure Context Fix

在局域网上通过普通 HTTP 修复 DeepSeek Harness Web GUI:在 dsh bundle 代码运行前注入一个由 getRandomValues 支持的 crypto.randomUUID polyfill。无需修改官方源代码。

插件会安装到这里;不确定时保持 web。

npx -y @deepseek-ai/dsh plugin --profile web add github:Li-Mingshuang/dsh-secure-context-fix#6ef7a104d111064242b5200cf2745312bb4c1f2d
README兼容性版本

兼容性与来源证明

Secure Context Fix 以 dsh-secure-context-fix 发布,当前版本为 0.1.0。Plugin Hub 会校验它的 manifest,并保存精确安装来源,便于复现安装结果。

DSH 兼容范围
*
运行环境
any
发布来源
github
Registry 更新时间
2026/9/5

版本

0.1.0stable
2026/9/5

相关插件

正在加载相关插件…

最新版
0.1.0
DSH
*
HMR
重启进程
Tree shaking
未声明可安全裁剪
解包体积
未提供
文件数
未提供
Surface
any
许可证
MIT
发布源
github
GitHub
★ 0
周下载
0
最近提交
2026/9/5
查看源码 ↗
README Badge

点击下方 Badge 复制 Markdown,粘贴到 README 即可。

这是你的 Plugin?认领权益 · 优先安全扫描

验证 package.json 声明的 GitHub 仓库,即可管理这个公开页面。认领后,Hub 会优先安排当前版本的安全扫描,并在通过后公开展示结果。

认领这个 Plugin →
报告问题

相关插件

继续浏览 ui-customization 分类下经过校验的插件。

Web App@deepseek-ai/dsh-web-appdsh 浏览器界面捆绑包:位于 dsh-base 之上的 Web 补丁层,加上运行时粘合插件(提供前端 dist、Web 界面提示符、bash 运行时变量和 URL 行)Experimental Agent Team Web Profile@deepseek-ai/dsh-experimental-agent-team-web-profile用于 Agent Teams Remote 和 UI 插件的实验性 Web 配置层Client Ui Task Board@linxin666/dsh-client-ui-task-board面向 DSH Web GUI 的主机权威任务面板,支持实际会话执行、主机 cron 调度以及可选的跨平台空闲睡眠保护;以挂载方式提供,无需修改 DSH 源代码。Pet@linxin666/dsh-pet适用于 dsh Web GUI 的多宠物伴侣插件:由注册表驱动的浮动宠物,可响应模型活动,支持为每只宠物命名、抚摸/喂食互动以及亲密度评分

README

dsh-secure-context-fix

Fix the DeepSeek Harness Web GUI over plain HTTP on a LAN (e.g. from a phone).

Problem

crypto.randomUUID only exists in secure contexts (HTTPS or localhost). When you open the dsh Web GUI from another device over plain HTTP on your LAN (http://192.168.x.x:3080), the browser has no crypto.randomUUID, so every RPC crashes with:

crypto.randomUUID is not a function

Symptoms: workspace list never loads, the directory picker fails, sessions cannot be created — while http://127.0.0.1:3080 works fine on the same machine.

How this plugin fixes it

This plugin is a small host plugin that registers a webServer.tapIndex transform. When the GUI serves its index.html, the plugin injects a tiny inline <script> into <head> that installs a crypto.randomUUID implementation backed by crypto.getRandomValues() — which browsers do expose on insecure origins — before any dsh bundle code runs.

No official source changes, no polyfill library, no build step for users.

Install

From the directory containing this package (after cloning):

dsh plugin --profile web add ./dsh-secure-context-fix

Or from a git host:

dsh plugin --profile web add github:<you>/dsh-secure-context-fix

Then restart the profile:

dsh --profile web

First add from a git host may ask you to allow the package's build (allowBuilds) if a prepare script is present; this package ships no build step and plain JS, so no allowance is needed.

How to check it works

  1. Serve the GUI on all interfaces so a phone can reach it. The dsh CLI rejects --host 0.0.0.0 for safety, so patch the webserver row in the profile instead:

    # $DSH_HOME/profiles/web/cordis.patch.yml
    - id: webserver
      config:
        host: '0.0.0.0'
        port: !!js ctx.webStartup.port ?? 3080
    
  2. Allow inbound TCP 3080 in the firewall, ideally restricted to your LAN subnet:

    New-NetFirewallRule -DisplayName "dsh web 3080 (LAN)" -Direction Inbound -Protocol TCP -LocalPort 3080 -Action Allow -Profile Private -RemoteAddress 192.168.0.0/24
    
  3. On the phone (same Wi-Fi) open http://<your-LAN-IP>:3080. Workspace list, directory picker, and new sessions should now work.

Files

  • index.js — the plugin entry (name, inject, apply).
  • cordis.patch.yml — the bundle layer inserting the plugin row.
  • package.json — npm manifest declaring dsh.bundle.

Security notes

Binding the GUI to 0.0.0.0 exposes remote-code-execution-grade control of the agent to anyone who can reach the port. Only do this on a trusted network, and prefer restricting the firewall rule to your LAN subnet as shown above.

Upstream

This is a stop-gap for deepseek-ai/deepseek-harness discussions #4209 until the official repo replaces its three crypto.randomUUID() call sites (AbstractApiClient.mintRpcId, ui-conversation image draft ids, and llm createMessage) with getRandomValues()-based UUIDs. If you can patch the source, do that instead; this plugin helps users who cannot.