dshbase

Plugin directory / UI & Skins / dsh-plugin-qr-connect

dsh-plugin-qr-connect

Verified · install-tested on dsh mervyn-teo

✓ Actively maintained Builds on 11 official DSH packages

View on GitHub ↗ ← Back to plugin directory

3Stars
0Forks
0Open issues
JavaScriptLanguage
2026-08-15Last push
Cross-platformPlatform

What it does

DeepSeek Harness dynamic plugin: QR-code sidebar button for connecting mobile devices to the web UI

✅
Our take
Works — verified, early-stage project

DeepSeek Harness dynamic plugin: QR-code sidebar button for connecting mobile devices to the web UI It installs cleanly and boots without issues in our testing. It's early-stage but functional.

“Verified” means our automated CI actually ran dsh plugin add in a clean profile and it booted — nothing more. Feature descriptions and version compatibility are the author’s claims. This is not a security audit and not an endorsement of third-party code.

README

dsh-plugin-qr-connect

dsh-plugin-qr-connect banner — scan to connect any device to your DeepSeek Harness web UI

English | 中文

A DeepSeek Harness (DSH) Web
plugin that adds a QR-code button above the Settings button in the sidebar
footer. It runs a small auth-gated reverse proxy so a phone on the same network
(or the internet) can scan a QR code and open the web UI securely. It is a
persistent bundle plugin (a host half plus a browser half) that loads on every
boot.

Demo

dsh-plugin-qr-connect demo — click the QR button, scan, connect

What it does

  • Adds a full-width button (sidebar.footer.action, id qr-connect) stacked
    above the shipped Plugins button.
  • Opens a fading panel with two QR codes:
    • Local network — http://<lan-ip>:<port>/?auth=<secret>.
    • Public internet — http://<public-ip>:<port>/?auth=<secret> (blue).
  • The reverse proxy (a child node process on 0.0.0.0:<port>) validates the
    secret, issues a session cookie (default 30 days), and forwards to the
    loopback web UI — including WebSocket upgrades so live updates reach the phone.
  • The secret rotates every 30s by default and the QR refreshes to match
    (configurable; 0 disables auto-refresh).
  • Click a QR to copy its link; the public QR has an info tooltip.
  • A QR connect card under Settings → Plugins configures the proxy port,
    session length, and refresh interval.
  • English and Chinese UI via DSH's locale service.

Files

File Purpose
lib/index.js Host half — runs the reverse proxy and the /__qr/* state routes.
lib/client.js Browser half — the QR button and the settings card.
lib/proxy.cjs The auth-gated reverse proxy child process (HTTP + WebSocket).
cordis.patch.yml Composition patch that inserts the plugin row.
package.json Package metadata (dsh.bundle + dsh.client manifest).

Install

dsh plugin --profile web add github:mervyn-teo/dsh-plugin-qr-connect

Then restart dsh web — host bundles load at boot.

Defaults live in cordis.patch.yml (port, sessionDays, refreshSeconds).
Change them there (or in the profile's own cordis.patch.yml) and restart, or
adjust them at runtime from the settings card. The host half serves three
same-origin routes the browser half uses: GET /__qr/info,
POST /__qr/rotate, and GET|POST /__qr/config.

Requirements

  • DSH with the subprocess, fs, and webServer services mounted.
  • Internet access from the DSH host for the public-IP lookup
    (https://api.ipify.org).
  • The scanning device must be able to reach the proxy port (a host firewall may
    need an allow rule); the public QR also needs internet reachability
    (port-forwarding).

Local-IP and public-IP detection run in-process (no ip/curl/shell commands),
and manual secret rotation signals the proxy child over its stdin, so the host
half works on Windows, macOS, and Linux.

Security

The proxy exposes the full agent shell to anyone who can reach the port, gated
only by the 30s secret and the session cookie. Use a short session length and
treat this as a trusted-network convenience, not a hardened remote-access layer.

License

MIT

Install

🧩 Let your agent install it (recommended)

Install the catalog once, then DeepSeek Harness can find and install any plugin from this site automatically:

dsh plugin add dshbase-catalog

Then say "install dsh-plugin-qr-connect for me" — your agent finds it in the directory and installs it. Docs: dshbase-catalog · verified packs.

This plugin is GitHub source (not published to npm) — install it straight from the repo:

Web profile:

dsh plugin --profile web add github:mervyn-teo/dsh-plugin-qr-connect

Headless (CLI) profile:

dsh plugin --profile headless add github:mervyn-teo/dsh-plugin-qr-connect

Test report

Verified: L1 install + L2 load + L3 runtime from GitHub source on dsh 0.1.0-rc.6.

When to use it

Change how dsh looks or how you interact with it — a theme, a skin, or a new panel that reshapes the workspace.

Who it's for

Users who spend hours in the web UI and want it to look and feel the way they work.

For developers — extending it

Skins, panels, and theme tokens are the extension points — author a new skin, add a panel, or sync tokens with an upstream palette.

Security: not yet scanned — our daily static scan will cover it shortly.

Share this badge

More in UI & Skins

Browse all 7797 plugins →