Plugin directory / Network / dsh-randomuuid-polyfill
dsh-randomuuid-polyfill
Verified · install-tested on dsh Lehmaning
What it does
dsh client plugin that installs crypto.randomUUID on insecure origins (plain HTTP over a LAN address)
Works — verified, early-stage project
dsh client plugin that installs crypto.randomUUID on insecure origins (plain HTTP over a LAN address) It installs cleanly and boots without issues in our testing. It's early-stage but functional.
“Verified” means our automated CI actually ran dsh plugin add in a clean profile and it booted — nothing more. Feature descriptions and version compatibility are the author’s claims. This is not a security audit and not an endorsement of third-party code.
README
dsh-randomuuid-polyfill
A DeepSeek Harness client plugin that installs crypto.randomUUID when the page is not a secure context.
Why
crypto.randomUUID is gated to secure contexts (HTTPS, or localhost). When the dsh web UI is served over plain HTTP on a LAN address, every client RPC throws:
TypeError: crypto.randomUUID is not a function
The workspace picker ("open folder") is the first place most people hit it, because choosing a workspace issues a listDirectory RPC. The root cause is upstream: AbstractApiClient.mintRpcId() in packages/host/apiproxy/src/fetch/client.ts calls crypto.randomUUID() unconditionally, and the composer's browserDraftAttachment() in packages/client/ui-conversation/src/client/service.ts does the same.
This plugin restores the missing API at boot, backed by crypto.getRandomValues (available on insecure origins), so the UI works over plain HTTP without waiting for an upstream fix.
Install
Build and install the package into the harness environment, then start the web UI:
pnpm build
npm install <path-to-this-package>
npx @deepseek-ai/dsh web
The harness discovers the plugin from the dsh manifest field and injects the client bundle at boot (immediately: true).
Alternatives
- Open the UI at
http://localhost:3080(SSH tunnel into the host) —localhostis a secure context, so nothing is needed. - The proper fix lives in the source: use a
crypto.getRandomValues-based UUID inmintRpcId/browserDraftAttachment. A patched fork is available at Lehmaning/deepseek-harness on thefix/randomuuid-secure-contextbranch.
License
MIT
Install
Install the catalog once, then DeepSeek Harness can find and install any plugin from this site automatically:
dsh plugin add dshbase-catalog Then say "install dsh-randomuuid-polyfill for me" — your agent finds it in the directory and installs it. Docs: dshbase-catalog · verified packs.
This plugin is GitHub source (not published to npm) — install it straight from the repo:
Web profile:
dsh plugin --profile web add github:Lehmaning/dsh-randomuuid-polyfill Headless (CLI) profile:
dsh plugin --profile headless add github:Lehmaning/dsh-randomuuid-polyfill Test report
Verified: L1 install + L2 load + L3 runtime from GitHub source on dsh 0.1.0-rc.6.
When to use it
Give the agent network access — requests, APIs, proxies, or protocols — so it can reach external systems.
Who it's for
Users whose tasks touch the network — calling APIs, fetching resources, or talking to remote services.
For developers — extending it
Adapters and request shaping are the seams — add protocols, auth handlers, retries, and endpoint abstractions.