# dsh-lan-gate English | [中文](README.zh.md) Password gate + CIDR allowlist + proxy-header deny for [DeepSeek Harness](https://github.com/deepseek-ai/deepseek-harness) web. `dsh web --host 0.0.0.0` is rejected by the CLI. This bundle sets `webserver.host` to `0.0.0.0` through the official composition layer, then requires a password before the UI or `/api` is reachable from the LAN. ## Install ```sh dsh plugin --profile web add dsh-lan-gate ``` Or from GitHub: ```sh dsh plugin --profile web add github:maxesisnclaw/dsh-lan-gate ``` Then open `http://127.0.0.1:3080/dsh-lan-full/login` and set a password (loopback only). After that, LAN clients get the login page. Settings → **LAN access** / **LAN 访问** edits CIDRs, proxy-header policy, and the password. The settings section and login page follow dsh's official `zh`/`en` locale. ## What it does | Control | Default | |---|---| | Listen on all interfaces | yes (bundle patch) | | Password | unset until you set it from loopback | | Inbound IPv4 CIDRs | `10.0.0.0/8`, `172.16.0.0/12`, `192.168.0.0/16` | | Reject `X-Forwarded-*` / `Forwarded` / `Via` | yes | | Loopback bypasses password | yes (recovery) | Policy file: `$DSH_HOME/lan-gate.json` (mode `0600`). The password is stored as a scrypt verifier, never as plaintext. Session tokens are random 32-byte values; only their SHA-256 is kept in memory. ## Residual risk This is not a TLS terminator. On plain HTTP a LAN observer can still sniff the password and cookie. Do not put this on the public internet. Do not sit it behind a reverse proxy that adds forwarding headers — those requests are rejected on purpose. See [SECURITY.md](SECURITY.md). ## License MIT