插件目录 / UI & Skins / dsh-plugin-qr-connect
dsh-plugin-qr-connect
已验证 · 实测可装 mervyn-teo
功能简介
二维码侧边栏按钮,连接移动设备
可用 — 实测通过,早期项目
二维码侧边栏按钮,连接移动设备 实测能干净安装、正常启动。早期项目,但功能可用。
「已验证」表示我们的自动化 CI 在干净 profile 里实际执行了 dsh plugin add 并启动成功——仅此而已。功能描述与版本兼容性均为作者声明。这不是安全审计,也不代表对第三方代码的背书。
README
dsh-plugin-qr-connect
English | 中文
A DeepSeek Harness (DSH) Web
plugin that adds a QR-code button above the Settings button in the sidebar
footer. It runs a small auth-gated reverse proxy so a phone on the same network
(or the internet) can scan a QR code and open the web UI securely. It is a
persistent bundle plugin (a host half plus a browser half) that loads on every
boot.
Demo
What it does
- Adds a full-width button (
sidebar.footer.action, idqr-connect) stacked
above the shipped Plugins button. - Opens a fading panel with two QR codes:
- Local network —
http://<lan-ip>:<port>/?auth=<secret>. - Public internet —
http://<public-ip>:<port>/?auth=<secret>(blue).
- Local network —
- The reverse proxy (a child
nodeprocess on0.0.0.0:<port>) validates the
secret, issues a session cookie (default 30 days), and forwards to the
loopback web UI — including WebSocket upgrades so live updates reach the phone. - The secret rotates every 30s by default and the QR refreshes to match
(configurable;0disables auto-refresh). - Click a QR to copy its link; the public QR has an info tooltip.
- A QR connect card under Settings → Plugins configures the proxy port,
session length, and refresh interval. - English and Chinese UI via DSH's locale service.
Files
| File | Purpose |
|---|---|
lib/index.js |
Host half — runs the reverse proxy and the /__qr/* state routes. |
lib/client.js |
Browser half — the QR button and the settings card. |
lib/proxy.cjs |
The auth-gated reverse proxy child process (HTTP + WebSocket). |
cordis.patch.yml |
Composition patch that inserts the plugin row. |
package.json |
Package metadata (dsh.bundle + dsh.client manifest). |
Install
dsh plugin --profile web add github:mervyn-teo/dsh-plugin-qr-connect
Then restart dsh web — host bundles load at boot.
Defaults live in cordis.patch.yml (port, sessionDays, refreshSeconds).
Change them there (or in the profile's own cordis.patch.yml) and restart, or
adjust them at runtime from the settings card. The host half serves three
same-origin routes the browser half uses: GET /__qr/info,POST /__qr/rotate, and GET|POST /__qr/config.
Requirements
- DSH with the
subprocess,fs, andwebServerservices mounted. - Internet access from the DSH host for the public-IP lookup
(https://api.ipify.org). - The scanning device must be able to reach the proxy port (a host firewall may
need an allow rule); the public QR also needs internet reachability
(port-forwarding).
Local-IP and public-IP detection run in-process (no ip/curl/shell commands),
and manual secret rotation signals the proxy child over its stdin, so the host
half works on Windows, macOS, and Linux.
Security
The proxy exposes the full agent shell to anyone who can reach the port, gated
only by the 30s secret and the session cookie. Use a short session length and
treat this as a trusted-network convenience, not a hardened remote-access layer.
License
安装
装一次目录插件,之后本站所有插件都能让 DeepSeek Harness 自动找、自动装:
dsh plugin add dshbase-catalog 然后对 agent 说「帮我装 dsh-plugin-qr-connect」,它会在目录里找到并自动安装。文档:dshbase-catalog · 已验证场景包。
该插件是 GitHub 源码(未发 npm)——直接从仓库装:
Web profile:
dsh plugin --profile web add github:mervyn-teo/dsh-plugin-qr-connect Headless(CLI)profile:
dsh plugin --profile headless add github:mervyn-teo/dsh-plugin-qr-connect 实测报告
验证通过:从 GitHub 源码完成 L1 安装 + L2 加载 + L3 运行(dsh 0.1.0-rc.6)。
使用场景
改变 dsh 的外观或交互方式——一套主题、皮肤或新面板,重塑工作区。
适合谁
在 web UI 里一待几小时、想让它按自己的习惯好看又好用的人。
二次开发建议
皮肤、面板和主题 token 是扩展点——写新皮肤、加面板,或与上游配色同步 token。