# dsh-lan-gate [English](README.md) | 中文 给 [DeepSeek Harness](https://github.com/deepseek-ai/deepseek-harness) Web 加密码门禁、入站 CIDR 白名单,以及 proxy header 拒绝。 CLI 会拒绝 `dsh web --host 0.0.0.0`。本插件通过官方 composition 层把 `webserver.host` 设成 `0.0.0.0`,然后要求局域网客户端先登录,才能打开 UI 或 `/api`。 ## 安装 ```sh dsh plugin --profile web add dsh-lan-gate ``` 或从 GitHub: ```sh dsh plugin --profile web add github:maxesisnclaw/dsh-lan-gate ``` 然后打开 `http://127.0.0.1:3080/dsh-lan-full/login` 设置密码(仅本机回环)。之后局域网客户端会看到登录页。 设置 → **LAN 访问** 可改 CIDR、proxy header 策略和密码。设置页和登录页走 dsh 官方的 `zh`/`en` 语言。 ## 做什么 | 控制 | 默认 | |---|---| | 监听所有网卡 | 是(bundle patch) | | 密码 | 未设置,需从回环设置 | | 入站 IPv4 CIDR | `10.0.0.0/8`、`172.16.0.0/12`、`192.168.0.0/16` | | 拒绝 `X-Forwarded-*` / `Forwarded` / `Via` | 是 | | 本机回环免密 | 是(抢救用) | 策略文件:`$DSH_HOME/lan-gate.json`(权限 `0600`)。密码存 scrypt 校验值,从不存明文。Session token 是 32 字节随机值,磁盘上只留 SHA-256。 ## 剩余风险 这不是 TLS 终结器。明文 HTTP 上,局域网旁观者仍能嗅探密码和 cookie。不要放到公网。不要放在会加 forwarding header 的反代后面——这类请求会被故意拒绝。 见 [SECURITY.md](SECURITY.md)。 ## License MIT