AcidGr/dsh-web-lan-access

DeepSeek Harness (dsh) Web plugin

dsh-web-lan-access fixes a boot-critical bug that breaks the DSH Web UI over plain HTTP from non-loopback addresses: the UI calls crypto.randomUUID() in boot-critical paths (RPC id minting, message ids, draft attachments), and that Web API exists only in secure contexts (HTTPS or http://localhost/127.0.0.1). The plugin injects a small RFC 4122 v4 polyfill built on crypto.getRandomValues (available on insecure origins) as the first script in <head>, before the boot manifest — so sessions and models render on LAN IPs, Tailscale IPs, or hostnames. On secure origins the polyfill is a no-op. The bundle patch also sets the bind host to 0.0.0.0 and re-derives the /api trust fence from every non-internal IPv4 (LAN 192.168.x, Tailscale 100.x, VPN), with MagicDNS hostname support via trustedHosts.

UI Enhancements ★ 16 updated 2026-08-16
View on GitHub ↗

Install

dsh plugin --profile web add dsh-web-lan-access

Installed from npm with dsh plugin --profile web add dsh-web-lan-access (or from git with dsh plugin --profile web add github:AcidGr/dsh-web-lan-access for local development). Restart dsh web, then hard-refresh the browser. A manual offline install (cp -r + symlink + cordis.patch.yml insert) is also documented. The plugin is self-contained: its bundle patch sets the webserver bind host to 0.0.0.0 directly (the CLI --host 0.0.0.0 flag is hard-rejected on newer harness versions) and widens the /api trust fence automatically, so no --host flag is needed.

Compatibility

DeepSeek Harness Web UI (Linux/macOS/Windows/Android). Uses the webserver's official index-tap extension point (webServer.tapIndex) to inject a crypto.randomUUID polyfill; version-independent (only transforms the served index.html), no product source modified, fully reversible.

Details

Recent updates

The current README documents the polyfill injection, the automatic 0.0.0.0 bind and /api trust-fence widening, MagicDNS hostname configuration, the loopback-pinned privileged API limitation (settings./credentials./llm.discoverModels return 403 from remote origins on unmodified builds), verification via curl | grep lan-access-polyfill, and the security warning about unauthenticated network exposure.

FAQ

Why does the DSH Web UI break on a LAN IP?
The UI calls crypto.randomUUID() in boot-critical paths, and that API exists only in secure contexts; over plain HTTP from a non-loopback address every RPC throws. The plugin polyfills it with crypto.getRandomValues.
Do I need the --host 0.0.0.0 flag?
No — the CLI flag is hard-rejected on newer harness versions, and the plugin's bundle patch sets the webserver bind host to 0.0.0.0 directly.
Is it safe on a public network?
The README warns that binding 0.0.0.0 makes the agent reachable without authentication by anyone on the same network; use only on trusted networks, restrict with a firewall, or expose through Tailscale/reverse proxy.

Alternatives

flymysql/dsh-remote · juanwang-buaa/dsh-full-remote · liguobao/deepseek-harness-remote

More plugins in UI Enhancements

Browse more in UI Enhancements

Guides for UI Enhancements plugins