dsh-trusted-host-is-loopback
A dsh bundle that makes the authenticated Web UI page count as loopback, so
Host-backed settings (Settings → Models, the first-run API-key step, the preview
notice) work when dsh is reached through a reverse proxy instead of 127.0.0.1.
dsh already authenticates every browser that reaches the Web UI — the
Host/Origin trust fence declared with --trusted-host / trustedHosts, plus
the browser-session cookie — but it still classifies a non-loopback page as
remote and caps Host-backed features. This bundle flips that one client-side
flag. ownsHost is a classification only: the server's authentication and its
Host/Origin fence are untouched.
Install
dsh plugin --profile web add @exagone313/dsh-trusted-host-is-loopback
Restart dsh afterwards.
Remove
dsh plugin --profile web remove @exagone313/dsh-trusted-host-is-loopback
Restart dsh afterwards.
Notes
- No configuration.
- The Host/Origin trust fence is the boundary: only authorities you declared trusted should reach the Web UI. See SECURITY.md.
- The
webserver/index-injecthook belongs to@deepseek-ai/dsh-host-webserver; a future rename would require a plugin update. - Tested against dsh
0.2.0-rc.2.
No comments yet. Be the first to write one.