dsh-wecom-plugin

by kenny245

通知与集成github收录于 08-23

自托管 TypeScript 服务 + 原生 Cordis 插件:合规的企业微信会话内容存档检索与带引用的待办草稿

Self-hosted TypeScript service plus native Cordis plugin for compliant WeCom Conversation Content Archive search and cited todo drafts.

安装

dsh plugin --profile web add github:kenny245/dsh-wecom-plugin

GitHub 源码安装:首次需按提示配置 allowBuilds 构建授权后重试

安装与环境配置指引、插件开发教程见 DSH 中文社区文档 ↗

安装即在你的机器上以你的权限运行第三方代码——它可读写文件、使用凭据、访问网络,DSH 的工具审批不会为插件代码加沙箱。「检测到 manifest」仅代表发现 dsh.bundle / dsh.plugin 清单,不构成兼容性或安全审查;安装前请审阅源码,不熟悉的插件先在不含密钥的环境试用。

README

目录

Self-hosted TypeScript service plus native Cordis plugin for compliant WeCom Conversation Content Archive search and cited todo drafts.

Community submission metadata

Field Current value
Plugin name dsh-wecom-archive
Repository URL github.com/kenny245/dsh-wecom-plugin
Relationship to DeepSeek A native Cordis plugin for DeepSeek Harness. This is an integration project; do not present it as an official DeepSeek AI product without explicit approval.
Open-source license MIT
Copyright ownership The current LICENSE names omdsh-dev; confirm the legal copyright holder before public release.
Maintenance status MVP foundation; pre-publication. No primary maintainer has been confirmed yet.
Primary maintainer PRIMARY_MAINTAINER_NAME_TO_BE_CONFIRMED

The clean, paste-ready Discussion text is in the copy-ready community submission. The submission draft retains its internal posting checklist.

Scope

  • Authorized search and todo drafts only; no messages, task creation, media download, MCP adapter, hosted control plane, or archive export.
  • The DSH plugin exports native name / apply and exposes only search and draftTodos. It never ingests, decrypts, or stores WeCom archives.
  • The customer deployment keeps all WeCom credentials, RSA private keys, plaintext, and encryption keys. The official Finance SDK is a local sidecar dependency and is not redistributed here.

Controls

  • Employee: participating archived conversations only.
  • Manager: active permitted-team grant only.
  • Compliance admin: active departmental grant and an audit reason.
  • External conversation: server-side effective-consent lookup required.
  • AES-256-GCM encrypted message payloads, versioned data keys, cursor-safe sync, and HMAC-linked audit events.

Read architecture, threat model, and deployment before deploying.

Installation and usage

The source repository is public, but the plugin is not yet published to a package registry. Install it from a source checkout in the customer-controlled deployment environment. It requires Node 22.19+, Corepack/pnpm, PostgreSQL, and a customer-local WeCom SDK sidecar.

git clone https://github.com/kenny245/dsh-wecom-plugin.git
cd dsh-wecom-plugin
corepack enable
pnpm install --frozen-lockfile
psql "$DATABASE_URL" -f infra/postgres/migrations/001_initial.sql
cp .env.example .env
pnpm run check
pnpm --filter @omdsh/wecom-archive-service start

Never put real secrets in .env.example, Docker Compose, committed config, or issues.

Cordis wiring

import wecomArchive from '@omdsh/dsh-wecom-plugin'

ctx.plugin(wecomArchive, {
  serviceUrl: 'https://archive.internal.example',
  audience: 'dsh-wecom-archive',
  timeoutMs: 3000,
  serviceToken: process.env.DSH_WECOM_PLUGIN_TOKEN!
})

The backend resolves the actor identity from the token; request payloads cannot select a role.

After starting the archive service, use the configured plugin command or its exposed search/todo-draft operation. A todo draft is only a review artifact: the MVP never sends a message, creates a task, or changes WeCom.

Risks, limitations, and compatibility

  • This is a pre-publication MVP for compliant WeCom Conversation Content Archive deployments, not unrestricted employee visibility. Customers remain responsible for their archive entitlement, consent, retention, and access policy.
  • External conversations are searchable only when the configured consent resolver reports effective archive consent. Missing or incorrect consent data fails explicitly; it does not expand access.
  • The service performs a bounded PostgreSQL candidate scan after authorization. It is intentionally conservative but needs additional indexing before use with unbounded archive volumes.
  • Attachments/media, automatic task creation, automatic message sending, managed hosting, and MCP are outside the MVP. Todo drafts require human verification.
  • Compatibility target: Node.js >=22.19.0, pnpm >=11.19.0, PostgreSQL, a compatible DeepSeek Harness/Cordis host, and a customer-supplied compatible WeCom archive SDK sidecar. DSH/Cordis and SDK API changes may require updates.

Checks

pnpm run typecheck
pnpm run test
pnpm run build

MIT. See CONTRIBUTING.md and SECURITY.md.

原始 README: https://github.com/kenny245/dsh-wecom-plugin/blob/codex/dsh-wecom-plugin-mvp/README.md ↗

同类插件

查看全部 →
通知与集成alvinunreal

dsh

将 DeepSeek Harness 的生命周期状态、错误与审批请求,桥接到本地运行的 OpenPets 桌面伙伴。

查看详情
1081github+08-21
通知与集成tencent-connect

dsh-qqbot

让 QQ Bot 接入 DeepSeek Harness(dsh)的官方插件

查看详情
55github+08-17
通知与集成omdsh-dev

dsh-open-in-vscode

从 Web GUI 一键在 VS Code 中打开工作区目录。

查看详情
39github+08-13
通知与集成omdsh-dev

dsh-notification

回合完成桌面通知,按结果分控 + 关键词过滤。

查看详情
38github+08-13
通知与集成THEWOLFWALKER

dsh-notifier

DSH 统一通知推送与远程控制:一个 `notify()` API 打通 25+ 渠道(Telegram / 钉钉 / 飞书 / 企业微信 / QQ 机器人 / WxPusher / PushPlus / Server 酱 / Bark / Discord / Slack / ntfy / webhook 等),timeSensitive / active / passive 分级路由并重试;五通道反向审批(Telegram 按钮 / 飞书卡片 / QQ / WxPusher / 微信 iLink);QQ/钉钉/飞书官方扫码登录;本地 Web 管理台;多 agent 路由;系统桌面通知——以及**手机指挥中心**:在手机上发 `!status` / `!stop` / `!retry` 遥控 agent,通知带可操作按钮(查看结果 / 重试 / 日志,点击回调 agent)。密钥脱敏、工具限流、零运行时依赖。

查看详情
27github+08-16
通知与集成wzj998

chatccc

飞书(Lark)或微信(WeChat)聊天控制 DeepSeek Harness / Claude Code / Cursor / Codex / CCC Agent

查看详情
22github+08-23