DSH HUB
HomePlugin StorePlugin PacksCommunityRankingsResourcesPublish Guide
Plugin source
Back to catalog

realjhen123 /

realjhen123/dsh-totp-proxy

Verified

This plugin has no description yet.

★ 0 Stars0 Forks0 IssuesN/A Community rating0 Confirmed installs
View on GitHub
READMESource: master@6283fb86

NOTICE

human-written

由人类完成

This project is 100% vibe-coding product, make for deepseek-harness access control base on TOTP.

Design for public network environment but do not using it on real public network.

If you want to using this plugin, make sure nginx can only proxy to 3090 and 3080 could not be access on external.

For totp, you can use Apple Passwords or 1Password or something like.

Configure page must be access via 127.0.0.1 so if your dsh on a virtual environment that have not GUI, for first time or forget totp, using ssh dsh@dsh -NL 3080:127.0.0.1:3080, then you can open 127.0.0.1:3080 for add qrcode.

For any configure, using ssh dsh@dsh -NL 3090:127.0.0.1:3090 you can config all about dsh-totp-proxy on 127.0.0.1:3090.

本项目由100% vibe-coding AI打造,用于给deepseek-harness添加一个基于TOTP验证的权限控制

请不要将本项目放在公网环境

如果你想用这个插件,确保你的nginx或任何反代只能到3090端口,3080端口只能本机访问

对于TOTP,你可以使用苹果的密码、1Password或其他类似物

配置页面只能通过本机访问,如果你在没有GUI的虚拟环境,对于第一次或忘记TOTP码,ssh dsh@dsh -NL 3080:127.0.0.1:3080可以帮助你创建ssh端口映射,你就可以在127.0.0.1:3080看到二维码

对于修改配置,ssh dsh@dsh -NL 3090:127.0.0.1:3090创建端口映射,可以管理所有dsh-totp-proxy的配置

AI-written

由AI完成

dsh-totp-proxy

独立的 DSH/Cordis 插件 + 反向代理:内置 TOTP / 固定 token 登录,浏览器只持有可吊销的 dsg_session。

DSH 核心签发的 dsh-auth-* 是自包含 bearer cookie,浏览器拿到后即使再弹验证码也能在过期前直接调用 API。本代理把原始 cookie 留在服务端,浏览器只拿到随机 session;每个 HTTP 请求和 WebSocket upgrade 都先经过代理校验,删除服务端 session 即可立即吊销。

零运行时依赖,Node.js 22+(仅 node:http / node:https)。

架构

浏览器 --dsg_session--> Nginx :80/:443 --> dsh-totp-proxy 127.0.0.1:3090 --dsh-auth cookie--> DSH 127.0.0.1:3080

代理自己校验 TOTP / 固定 token,读取 DSH browser-session 签名密钥,直接签发 DSH 核心认可的 cookie。

快速开始

作为 DSH 插件:

dsh plugin --profile web add /home/coder/project/dsh-totp-proxy -w

可用 cordis.patch.yml 覆盖配置:

- id: dsh-totp-proxy
  config:
    host: 127.0.0.1
    port: 3090
    target: http://127.0.0.1:3080
    cookieSecure: true
    authMode: both

独立运行:

node totp-proxy.mjs

测试:

npm run check   # 语法检查 + node --test

认证

authMode 行为
totp 只接受 6 位验证码
token 只接受固定 token
both 两者任一(默认)

凭据首次运行自动生成,保存在 ~/.dsh/dsh-totp-proxy/:

  • totp.json — Base32 TOTP secret
  • token.json — 固定访问 token

连续失败达到上限(默认 10 次)会按 IP 锁定(默认 60 秒)。

配置项

常用环境变量(完整默认值见 src/server.mjs 的 DEFAULTS):

变量 默认 说明
DSH_TOTP_PROXY_HOST 127.0.0.1 监听地址
DSH_TOTP_PROXY_PORT 3090 监听端口
DSH_TOTP_PROXY_TARGET http://127.0.0.1:3080 DSH 上游
DSH_TOTP_PROXY_AUTH_MODE both totp / token / both
DSH_TOTP_PROXY_TOTP_SECRET 空 直接指定 Base32 secret
DSH_TOTP_PROXY_TOKEN 空 直接指定固定 token
DSH_TOTP_PROXY_SESSION_TTL_MS 1800000 代理 session TTL
DSH_TOTP_PROXY_COOKIE_NAME dsg_session 浏览器 cookie 名
DSH_TOTP_PROXY_COOKIE_SECURE false HTTPS 后置 1
DSH_TOTP_PROXY_BROWSER_SESSION_SECRET 空 DSH cookie 签名密钥
DSH_TOTP_PROXY_CREDENTIALS_FILE ~/.dsh/.credentials.yaml 读取签名密钥的文件
DSH_TOTP_PROXY_UPSTREAM_SESSION_PATH /api 上游会话校验路径

DSH_TOTP_PROXY_COOKIE_SECURE=1 必须与 HTTPS 一起使用;DSH 3080 和代理 3090 都不能直接暴露。

部署要点

  • 只暴露 Nginx(:80/:443),反代到 127.0.0.1:3090,并转发 Upgrade / Connection 以支持 WebSocket。
  • DSH 只监听 127.0.0.1:3080。
  • 设置 DSH_TOTP_PROXY_COOKIE_SECURE=1。
  • ~/.dsh/.credentials.yaml(含 client-connection/browser-session 密钥)必须保持 0600。

安全边界

能做到: 浏览器看不到 dsh-auth-*;删除服务端 session 立即吊销;所有 API / WebSocket 统一校验。

仍注意: dsg_session 是 bearer credential,被窃取后可在 TTL 内重放;必须 HTTPS + HttpOnly + SameSite=Strict + 短 TTL;session 在内存中,代理重启后需重新登录。

License

MIT

—/ 5

No ratings yet

Verified DSH bundle

Commit 6283fb867b5a

Community comments

No comments yet. Be the first to write one.

DSH HUB

A community index for DSH plugins. Not an official GitHub or DeepSeek AI product.

CommunityResourcesAPIAbout