DSH HUB
HomePlugin StorePlugin PacksCommunityRankingsResourcesPublish Guide
Plugin source
Back to catalog

xfqz86 /

xfqz86/dsh-web-fetch-allowlist

Verified

DSH 网页抓取白名单插件:复用官方传输链路,仅对可配置 CIDR(如 Clash fake-ip 段)放行,其余 SSRF 校验全部保留。纯 JS,无需构建。

★ 0 Stars0 Forks0 IssuesN/A Community rating0 Confirmed installs
View on GitHub
READMESource: main@b9ee2766

dsh-web-fetch-allowlist

DSH 的白名单网页抓取 provider 插件(服务端 Host,无浏览器端,纯 JS 无构建)。

在 ctx.web 注册 http-allowlist 抓取 provider:薄套壳,复用官方 @deepseek-ai/dsh-web-fetch-http 的传输/重定向/钉扎/解码,仅注入白名单 DNS 解析,用于 Clash fake-ip 等本地覆写场景。

结构:lib/allowlist.js(CIDR 白名单)+ lib/resolver.js(注入官方的 DNS 校验)+ lib/index.js(换 id 注册)。lib/ 即源码,直接推 GitHub;验证只跑 pnpm test。

安全模型(没有抛弃校验)

白名单是“窄例外”,其余校验全部保留:

  • URL 层:仅 http:/https:、禁内嵌凭据、长度 ≤2048。
  • DNS 层:单次解析、任一答案非公网即拒绝整个答案集;白名单命中才放行;连接钉扎到已校验地址集(防 TOCTOU);IPv6 做 DNS64/NAT64 翻译复核;IP 字面量同样校验。
  • 传输层:仅跟随同源重定向并逐跳重校验;超时、字节/字符上限;Content-Type 仅解码文本系;charset 显式解码。
  • 代理层:复用 proxyRouteFor 同一路由答案;白名单外 IP 字面量不走代理快捷路径。

默认白名单(开箱即用,可覆盖):

  • 198.18.0.0/16(Clash fake-ip IPv4)
  • 2001:2::/48(被劫持的 fake IPv6 AAAA)
  • fd00::/8(Clash fake-ip IPv6 ULA)

0.0.0.0/0、::/0 等宽条目会显著弱化 SSRF 防护,仅限可信环境。

安装(标准 cordis.patch 模式)

dsh plugin --profile web add "link:<本目录>"

cordis.patch.yml 已自带挂载与切换(web.fetchProvider: http-allowlist),改动后服务端需重启 dsh。卸载:

dsh plugin --profile web remove dsh-web-fetch-allowlist

配置

全部可选,patch 的 config 字段:

字段 默认 说明
maxResponseBytes 5000000 响应体最大字节数
maxBodyChars 100000 解码后最大字符数
timeoutMs 30000 抓取超时
maxRedirects 5 同源重定向跳数
userAgent dsh-web-fetch-allowlist/0.1.0 请求头
allowedNonPublicCidrs 上述三段 被视为公网的额外 CIDR;[] 即严格公网策略
—/ 5

No ratings yet

Verified DSH bundle

Commit b9ee276675cd

Community comments

No comments yet. Be the first to write one.

DSH HUB

A community index for DSH plugins. Not an official GitHub or DeepSeek AI product.

CommunityResourcesAPIAbout