dsh-web-startup-auth

GDWhisper

替换 dsh web 启动器以允许绑定 0.0.0.0,并以账号密码登录为门槛:签名会话 cookie、/api 路由保护、设置面板认证标签页,以及轮换签名密钥使全部会话失效的重置 CLI。

Replaces the dsh web startup to allow binding 0.0.0.0, gated by username/password login: signed session cookies, /api route protection, an auth tab in the settings panel, and a reset CLI that rotates the signing key to invalidate all sessions.

安装命令

dsh plugin --profile web add github:GDWhisper/dsh-web-startup-auth

该命令来自上游目录,本站的自动审核尚未覆盖它——执行前请自行核对仓库。

安装后运行 dsh --profile web --dump-config 并重启对应 profile。插件会以你的本机权限运行第三方代码,安装前请检查源码。

信号

GitHub Stars13
30 天下载—
分发方式Git
收录时间2026-08-19

第三方安全扫描

6 项严重code-exec ×2shell ×4扫描 13 个文件

该结果基于 3ea0399,仓库已有更新提交 70f08b4,结论可能已过时。

静态代码分析结果,数据来自 dsh.so(扫描于 2026-08-22)。它检查的是代码里的危险调用模式,不等同于安全审计,也和本站「已验证」(真机启动验证)是两种不同的信号。

相关链接

同类插件