Bernardxu123/dsh-mobile-gate

LAN mobile gateway for DeepSeek Harness (DSH): first-visit approval, per-device tokens, rate limiting, mobile layout injection.

dsh-mobile-gate lets phones and tablets on your LAN safely reach your local DeepSeek Harness Web UI, with a mobile-friendly layout injected automatically. A device's first visit shows a 'Waiting for approval' page and cannot reach DSH until you approve it on the PC admin page; approval issues a one-time per-device token bound to that browser. It adds per-IP rate limiting (120 req/min by default, 429 beyond), a loopback bypass so the desktop experience is unchanged, and mobile CSS scoped to html[data-lan-device="phone"] (compact pills for the permission/model selectors plus a crypto.randomUUID polyfill that stops the SPA white-screening over plain HTTP). The admin page at /lan-gate/admin lets you approve, deny, revoke, or set the layout kind (phone / desktop / auto) per device.

UI Enhancements ★ 3 updated 2026-08-14
View on GitHub ↗

Install

git clone https://github.com/Bernardxu123/dsh-mobile-gate.git && dsh plugin --profile web add ./dsh-mobile-gate

Option 0 is the standard install: run dsh plugin --profile web add ./dsh-mobile-gate in the directory containing the repo (the README also documents the git clone step), and because the repo declares a dsh.bundle manifest the config layer activates automatically with no manual patch. The README also documents a static cordis.patch.yml mount (Option A, persists across restarts) and a dynamic plugin registration (Option B). No registry package is claimed.

Compatibility

DeepSeek Harness Web profile. The gateway is a standalone, zero-dependency Node child process (~30KB single file) isolated from the DSH host; DSH's own webserver stays bound to 127.0.0.1 and the /api trust fence is untouched. Intended for trusted LANs only -- the README states it has no independent auth layer, so verify a device's identity before approving. The admin API is loopback-only.

Details

Recent updates

The README documents the first-visit approval flow with per-device token and cookie binding, the isolated child-process design that leaves DSH's /api fence untouched, the config environment variables (LAN_GATE_PORT=3088, LAN_GATE_HOST=0.0.0.0, LAN_GATE_TARGET_PORT=3080, LAN_GATE_RATE_LIMIT=120), the loopback-only admin API, persistence in ~/.dsh/lan-gate-state.json, and the mobile CSS scope. It credits dsh-lan-gate and dsh-lan-access as inspirations.

FAQ

How do I install dsh-mobile-gate?
The README's standard install is dsh plugin --profile web add ./dsh-mobile-gate run from the cloned repo (it declares a dsh.bundle manifest, so no manual patch is needed); static cordis.patch.yml mount and dynamic-plugin options are also documented.
How does a phone get access?
Connect the phone to the same Wi-Fi and open the gateway address (default port 3088); it shows 'Waiting for approval'. On the PC admin page pick a layout kind (phone / desktop / auto) and click Allow -- the phone then claims its token and lands in the DSH Web UI.
Is it safe to expose on my LAN?
The README is explicit: there is no independent auth layer, so use it only on trusted LANs, verify device identity before approving, and consider 'Revoke all' periodically. The gateway is an isolated child process so a crash cannot take DSH down.

Alternatives

TZHR-invest/dsh-plugins#dsh-lan-gateway · lehhair/dsh-mobile · good-boy4069/dsh-mobile-remote

More plugins in UI Enhancements

Browse more in UI Enhancements

Guides for UI Enhancements plugins