request-frame-preview
Preview and download the exact request frame that DeepSeek Harness sends to
the model for a session: the full system prompt, the tool declarations
(tools), and the wire message array (system → user / assistant /
tool-result in order), rebuilt from the session log.
A small DSH plugin with a host half (one read-only HTTP endpoint) and a browser
half (a "请求预览 / Request preview" button in the session header).
Install
dsh plugin --profile web add request-frame-preview
or from a local checkout:
dsh plugin --profile web add /path/to/request-frame-preview
Restart dsh web (or let the plugin market restart it) so the bundle is
loaded. A 请求预览 button then appears in the session header utilities,
next to the built-in "Session log" button.
What it does
Click the button to open an overlay showing, top to bottom:
- ① system prompt — message
#0 of the wire array (collapsed by default).
- ② tools — the tool declarations carried by the request, one
tool row each; click a row to see its parameters.
- ③ messages — the wire message array from
#1 on, with user,
assistant, tool-result chips, tool_call_ids, reasoning content and
tool_calls expanded inline.
下载 JSON / Download JSON saves the whole frame (config + system + tools
with full parameter schemas + messages) as dsh-request-<sessionId>.json.
How the data is produced
- Live session first:
requestHeader() and deriveMessages() — the very same
folds the agent loop reads when it builds each request.
- Cold session fallback:
sessionQuery.readSession + readSurface from the
durable log.
- Wire expansion mirrors the DeepSeek chat-completions adapter's text path:
the system prompt becomes message
#0; each tool-result block becomes its
own role: "tool" message; assistant text, reasoning and tool_calls are
split into their wire fields.
Layout
package.json dsh.bundle.patch -> ./cordis.patch.yml; dsh.client.platform web
cordis.patch.yml inserts the plugin row into the profile layer stack
lib/index.js host half: registers GET /request-frame-preview/api
lib/client.js browser half (window.__ModuleLoader__ bundle)
Security notes
- The endpoint is read-only (
GET/HEAD) and serves no state mutation.
- Cross-origin requests are rejected when an
Origin header is present and
does not match Host; requests without Origin (curl, <a download>)
are allowed, mirroring dshmarket's GET route convention.
- This is a debugging aid: it exposes the session's full system prompt, tool
schemas and message contents to anyone who can reach the endpoint. The host
endpoint is not a security boundary.