sperictao/dsh-client-connection-authz
sperictao★ 0TypeScript最后同步: 2026-08-16
Auth-capable replacement for DeepSeek Harness client connection
README 摘要
dsh-client-connection-authz DeepSeek Harness 0.1.0-rc.6 内置 connection 的完整替代包。它保留官方 HTTP、共享/独立 RPC、WebSocket 和浏览器 client 行为,并在所有远程入口前 增加一个由外部插件提供的 ConnectionRequestAuthorizer 。 设计 本包的 bundle patch 做两件事: 1. 用 id + name 双重匹配禁用内置 @deepseek-ai/dsh-client-connection ;如果上游改名,patch 会显式告警而不会 误伤复用该 id 的其它插件。 2. 插入 @dsh-external/dsh-client-connection-authz ,并强制注入 connectionRequestAuthorizer 。认证插件缺失或配置失败时,connection 不会以 匿名模式降级启动。 浏览器 bundle 来自官方 @deepseek-ai/[email protected] ,构建时 只替换模块表 id;脚本会校验上游精确版本和唯一 id,防止静默漂移。Host 源码基于 DeepSeek Harness commit 47f943859bef60e4160492346772ded9b24f765a ,来源见 NOTICE.md。 授权接口 facts 包含 transport、channel、endpoint、headers、TCP peer address,以及目标 要求的 authority: - trusted-host :普通 API、普通 RPC 和两个 WebSocket downlink。 - loopback :设置、凭据、宿主文件操作等特权 API;认证插件只有显式授予更高权限 才能让远程调用通过。 执行顺序固定为:Host/Origin/DNS-rebinding fence → 本地回环判断 → 外部 authorizer → body 读取/协议升级/业务 handler。有效本地旁路必须同时满足回环 Host 和回环 TCP peer;远端仅伪造 Host: 127.0.0.1 仍会进入 authorizer。共享 RPC 会在 授权前把 handler 与 authority 快照为同一 target,避免授权后切换 interceptor 的 时序绕过。 安装 这个包故意不能单独启用;profile 还必须安装一个提供 authorizer 的认证包。例如与 dsh-auth-tailscale 一起安装: 两个仓库目前是 private;上面的已验证路径使用当前 gh 登录为 Git 配置 HTTPS 凭据。也可以改用已配置公钥的 SSH URL…
在 GitHub 查看完整 README →分类
A public gallery of animated pets for Codex, Claude Code, DeepSeek Harness, Hermes, OpenCode, Gemini CLI, and more.
★ 3,841
edison7009/EchoBirdOne-click install + model switch:Claude Code,Codex CLI (OpenAI), Grok Build (xAI), DeepSeek Harness, Kimi Code (Moonshot) ,Qwen Code,Aider,OpenCode,MiMo Code (Xiaomi),ZCode (Z.AI),OpenClaw,Pi,OpenScience,Vibe-Trading,Claude Desktop (3P profile),ChatGPT desktop,OpenCode Desktop,
★ 3,028
hyhmrright/brooks-lintAI code reviews grounded in 12 classic engineering books — decay risk diagnostics with book citations, severity labels, and 6 analysis modes including full-sweep auto-fix
★ 1,356