English | 中文
本仓库是 deepseek-ai/deepseek-harness 的 fork,在保持原版全部功能的基础上,增加了 公网部署支持。
源码补丁 — packages/client/connection/src/index.ts(第 147 行)
原版 dsh 对敏感 API(settings、credentials、agentPreset、llm.discoverModels 等)硬编码了 仅限回环地址(127.0.0.1) 访问,--trusted-host 参数对它们无效。本 fork 改为使用配置的 trustedHosts 列表,让 --trusted-host 对这些 API 也生效。
// 原版:硬编码空数组,只认 127.0.0.1
if (method !== undefined
&& PRIVILEGED_METHODS.has(method)
&& !isTrustedApiRequest(request, [])) { // ← 空数组,仅 loopback
return new Response('forbidden', { status: 403 })
}
// 本 fork:使用配置的 trustedHosts
if (method !== undefined
&& PRIVILEGED_METHODS.has(method)
&& !isTrustedApiRequest(request, trustedHosts)) { // ← 使用配置
return new Response('forbidden', { status: 403 })
}新增文件
| 文件 | 说明 |
|---|---|
deploy/nginx-dsh-web.conf |
Nginx 反代配置模板(HTTPS + Basic Auth + Host 重写) |
deploy/README.md |
部署目录说明 |
npm install -g @deepseek-ai/dshdsh web --port 4566 --host 127.0.0.1 --trusted-host <你的公网IP>:<端口>参考 deploy/nginx-dsh-web.conf,核心配置要点:
location / {
proxy_pass http://127.0.0.1:4566;
# Host 重写为回环地址,让敏感 API 能通过
proxy_set_header Host 127.0.0.1:4566;
proxy_set_header Origin "";
# ... WebSocket、SSL、Basic Auth 等
}htpasswd -bc /etc/nginx/.htpasswd-dsh <用户名> <密码>npx @deepseek-ai/dsh web默认在 http://127.0.0.1:3080 启动。更多用法见原版 Web UI 指南。
- Tag:
v0.1.0-rc.6-public - 下载: https://github.com/monikalnbo/deepseek-harness/releases/tag/v0.1.0-rc.6-public
--trusted-host是 DNS 反绑架栅栏,不是身份认证。公网部署必须配合 HTTPS + Basic Auth 使用。- 本 fork 将敏感 API 的信任判断从硬编码回环改为可配置,请确保用 nginx 的 auth_basic 补上认证层。
- 如需更高安全等级,建议通过 VPN 或 SSH 隧道访问。