# dsh-lan-gate

[English](README.md) | 中文

给 [DeepSeek Harness](https://github.com/deepseek-ai/deepseek-harness) Web 加密码门禁、入站 CIDR 白名单，以及 proxy header 拒绝。

CLI 会拒绝 `dsh web --host 0.0.0.0`。本插件通过官方 composition 层把 `webserver.host` 设成 `0.0.0.0`，然后要求局域网客户端先登录，才能打开 UI 或 `/api`。

## 安装

```sh
dsh plugin --profile web add dsh-lan-gate
```

或从 GitHub：

```sh
dsh plugin --profile web add github:maxesisnclaw/dsh-lan-gate
```

然后打开 `http://127.0.0.1:3080/dsh-lan-full/login` 设置密码（仅本机回环）。之后局域网客户端会看到登录页。

设置 → **LAN 访问** 可改 CIDR、proxy header 策略和密码。设置页和登录页走 dsh 官方的 `zh`/`en` 语言。

## 做什么

| 控制 | 默认 |
|---|---|
| 监听所有网卡 | 是（bundle patch） |
| 密码 | 未设置，需从回环设置 |
| 入站 IPv4 CIDR | `10.0.0.0/8`、`172.16.0.0/12`、`192.168.0.0/16` |
| 拒绝 `X-Forwarded-*` / `Forwarded` / `Via` | 是 |
| 本机回环免密 | 是（抢救用） |

策略文件：`$DSH_HOME/lan-gate.json`（权限 `0600`）。密码存 scrypt 校验值，从不存明文。Session token 是 32 字节随机值，磁盘上只留 SHA-256。

## 剩余风险

这不是 TLS 终结器。明文 HTTP 上，局域网旁观者仍能嗅探密码和 cookie。不要放到公网。不要放在会加 forwarding header 的反代后面——这类请求会被故意拒绝。

见 [SECURITY.md](SECURITY.md)。

## License

MIT
