dsh-tunnelmux-remote
by kexuejin
DeepSeek Harness移动远程控制插件,使用TunnelMux作为隧道后端:扫描配对二维码、一次性令牌、可撤销设备会话、移动/m页面。
Mobile remote control for the DeepSeek Harness web GUI with TunnelMux as the tunnel backend: scan-to-pair QR, one-time tokens, revocable device sessions, mobile /m page.
安装
dsh plugin --profile web add github:kexuejin/dsh-tunnelmux-remoteGitHub 源码安装:首次需按提示配置 allowBuilds 构建授权后重试
安装与环境配置指引、插件开发教程见 DSH 中文社区文档 ↗
安装即在你的机器上以你的权限运行第三方代码——它可读写文件、使用凭据、访问网络,DSH 的工具审批不会为插件代码加沙箱。「检测到 manifest」仅代表发现 dsh.bundle / dsh.plugin 清单,不构成兼容性或安全审查;安装前请审阅源码,不熟悉的插件先在不含密钥的环境试用。
README
目录
Mobile remote control for the DeepSeek Harness web GUI, with TunnelMux as the tunnel backend. Scan a QR code beside the sidebar to pair your phone, chat with your sessions from /m, and revoke any device at any time. The public URL comes from the local TunnelMux control API (cloudflared/ngrok) — no embedded tunnel binary in the plugin.
Built from scratch (2026-08-16) following the design in TunnelMux docs/plans/2026-08-16-dsh-tunnelmux-remote-design.md and referencing @linxin666/dsh-remote-web-ui (Apache-2.0) for the pairing model.
Features
- Scan-to-pair QR beside the official sidebar footer: one-time token, first accept consumes it, refresh invalidates the old QR immediately.
- Device sessions: HttpOnly cookie gate, presence tracking with offline detection, max 4 devices (oldest evicted), revoke all with one click.
- Mobile surface at
/m: session list (cursor pagination), create / rename / history / prompt / models — bridged through the host apiProxy with a strict method allowlist. - TunnelMux backend:
POST /v1/tunnel/startreturns the public URL synchronously (daemon waits for provider startup); the plugin observes status for the panel and never restarts the tunnel itself — the daemon ownsauto_restart. - Live updates: SSE
/api/pair/eventsfor the desktop panel and/m/api/events.muxfor the phone.
Install
Requires a running TunnelMux daemon (control API on 127.0.0.1:4765) and the DSH web profile:
cd ~/.dsh/profiles/web
dsh plugin add github:kexuejin/dsh-tunnelmux-remote # or link:/path/to/this/repo
Or add to cordis.patch.yml manually:
- insert:
- id: tunnelmux-remote
name: dsh-tunnelmux-remote
Configuration (settings namespace tunnelmux-remote)
| key | default | meaning |
|---|---|---|
enabled |
true |
master switch |
tunnelmuxBaseUrl |
http://127.0.0.1:4765 |
TunnelMux control API |
tunnelmuxApiToken |
'' (secret) |
optional Bearer token |
targetUrl |
http://127.0.0.1:3080 |
local GUI the tunnel exposes |
tunnelProvider |
cloudflared |
cloudflared or ngrok |
autoTunnel |
false |
start the tunnel on plugin load |
publicBaseUrl |
'' |
existing public entry (skips auto-tunnel) |
tokenTtlMs / offlineAfterMs / maxDevices |
10min / 25s / 4 | pairing tuning |
cookieName |
dsh_pair |
device cookie |
mobileEnterToSend |
true |
Enter sends in the phone chat box |
Security model
- One active token;
issue()replaces it, so a fresh QR invalidates the previous link immediately. - One-time accept; reuse returns
used(409). Tokens expire (default 10 min).stop()revokes every session and clears the token — the phone's next gated request gets 403. - Fences: control endpoints (
issue/stop/events) are loopback-only; phone endpoints (accept/heartbeat/status) allow loopback, LAN literals, or the public tunnel Host. Accept is rate-limited per IP (10 attempts / 30 s). - Mobile allowlist: only
workspace.list,session.*andmobile.preferencesare exposed over/m/api; everything else 403s.settings.*/credentials.*remain loopback-only host methods and are never reachable from a phone.
Development
npm install
npm run typecheck # tsc client + host
npm test # vitest (48 tests)
npm run build # tsdown: lib/index.js (host) + lib/mobile.js + client/client.js
node test/smoke-live.mjs # read-only probe of a live daemon at 127.0.0.1:4765
License
Apache-2.0.
原始 README: https://github.com/kexuejin/dsh-tunnelmux-remote/blob/main/README.md ↗
同类插件
查看全部 →
archify
Agent 技能:生成美观、可校验的架构图、工作流图、时序图、数据流图与生命周期图——自包含 HTML、带动画与清晰导出

dsh-turn-rewind
对话回退:基于持久 Change Ledger 回滚会话与工作区状态。

dsh-plugin-cc
把 DeepSeek Harness 接入 Claude Code:评审、批评、委派与会话导入

dsh-interconnect
跨实例互联:经 interconnect 服务在多个 DSH 实例间转发消息与事件。

dsh-chat-import
把 13 家 coding agent(Claude Code、Codex、ChatGPT、Cursor、Gemini、opencode 等)的完整对话历史导入为可续聊的 DeepSeek Harness 会话,并支持反向导出回 Claude Code。

dsh-crew
DSH 插件:从 Claude Code / Codex 向 DSH agent 派活——原生 subagent 进度、宿主内 worker 会话(分级预设),以及为纯文本宿主补上视觉与图像生成的多模态桥