Skip to main content

pilot-harness/packages/bundle/web-app

240Stars13Forks16Issues1Watchers

DSH browser surface composition package, overlays Web host and browser plugins on dsh-base, registers frontend dist, URL output, and DSH_WEB_URL variable.

Evidence4/5methodologySourceInstallMaintenanceDSH versionSecurity scan
Machine-auditedInstall commandRepo verifieddsh-plugin topicLicenseREADMEAI wiki

ⓘ This plugin is a sub-package of the op7418/pilot-harness monorepo — stars and activity count the whole repository.

Language
TypeScript
License
MIT
Branch
main
ai-agentcodepilotdeepseekdeepseek-harnessdesktop-appdshdsh-pluginelectron

Install

cmdweb profile
$ dsh plugin --profile web add @deepseek-ai/dsh-web-app

Run the command above in your terminal to install this plugin via the dsh CLI. You can switch Profile in the top-right corner. New to dsh? Read the beginner tutorial

Install via your agent

Install the DeepSeek Harness plugin op7418/pilot-harness/packages/bundle/web-app for me: review the repository at https://github.com/op7418/pilot-harness first, then run the install command and verify the plugin loads successfully.

Paste this instruction to the DSH Web GUI assistant — it will install and verify for you.

One-Line Description

DSH's browser surface bundle. Superimposes Web host and browser plugins on dsh-base, allowing dsh --profile web to start a local GUI service.

Core Capabilities

  • Superimposes Web host components (webserver, API gateway, workspace, projection cache, storage) and browser plugin combination (themes, layouts, sessions, commands, plugin center, model selection, etc.) on dsh-base
  • Parses command-line parameters such as --host / --port / --trusted-host / --help, and provides them to the host as webStartup service
  • Prints dsh web: http://127.0.0.1:<port> after port is ready and Loader config tree is settled, to avoid announcing an invalid application when sibling processes fail
  • Registers DSH_WEB_URL runtime variable in bash environment, resolved from the current listening URL on each invocation
  • Injects harness:source and app:web-surface segments into model system prompts, letting the model know it's in a GUI and that browser alternatives are not accepted
  • Samples IPv4 addresses from current network interfaces during listening phase, as the source for LAN trust fence

Technical Implementation

  • Language: TypeScript (ESM)
  • Key Dependencies: @deepseek-ai/dsh-web-frontend (frontend dist entry), commander (CLI parsing), @deepseek-ai/cordis & @deepseek-ai/cordis-plugin-loader (plugin host)
  • Architecture Pattern: Cordis function plugin + cordis.patch.yml bundle, overlaid on dsh-base via dsh.bundle.patch manifest field; host injects webStartup service, web-runtime samples bind dependency values and releases webRuntime to client trust fence
  • Entry Files: src/index.ts (web-runtime glue plugin) + src/startup.ts (CLI provider) + cordis.patch.yml (patch layer)

Use Cases

For end users to install the "dsh running in browser" experience: after installing a repository locally, anyone who wants a GUI instead of CLI/TTY can install this bundle; or developers need a dsh process with URL for host tools like Claude Code/Codex proxying. Also suitable as a resource supplier for dsh-frontend, where upstream packaging/distribution platforms use this bundle as the embedding point.

Prerequisites & Compatibility

DependencyMinimum VersionDescription
DSH0.1.0-rc.7+Same version as monorepo; this bundle is同级 to dsh-base / dsh-headless
Node^22.19.0 || >=24.0.0From monorepo root package.json engines.node field
PlatformCross-platformNo os/cpu restrictions declared; startup behavior doesn't depend on specific OS
Native ModulesNoneOnly uses Node built-ins node:os / node:module / node:url; no node-gyp dependencies

Installation

dsh plugin --profile web add github:op7418/pilot-harness/packages/bundle/web-app

Configuration

Bundle's own configuration (written in web-runtime line of cordis.patch.yml)

ConfigTypeDescriptionDefault
printUrlbooleanWhether to print dsh web: http://127.0.0.1:<port> to terminal after port is readytrue
surfaceContextbooleanWhether to inject "Web Surface" prompt segment and bash variable DSH_WEB_URL into modeltrue
trustedHostsstring[]Extra authority hosts passed via --trusted-host CLI parameter, appended to browser trust fence[]

CLI Parameters (passed via dsh --profile web)

ParameterUsage
--host <host>Listening host; binding 0.0.0.0 will be rejected and report usage error
--port <port>Listening port; passing 0 means let OS pick an available port
--trusted-host <authority...>Extra authority hosts allowed by browser trust fence, can be repeated
-h, --helpPrint help text for this application; service won't start during printing

FAQ

Q: What is this bundle and what is it for?

A: It's dsh's "Web Surface" bundle, overlaying all host and browser plugins needed for a browser interface on dsh-base. After installation, start a local GUI service via dsh --profile web.

Q: What's the relationship with dsh-headless and dsh-desktop?

A: These three are同级 surface bundles on dsh-base. web-app is the browser surface, headless is the headless surface, and desktop is the desktop application; they don't nest in each other; select one via --profile to load.

Q: Will it automatically open the browser after startup? Can it be disabled?

A: This bundle itself doesn't handle launching the system browser; it only prints one line dsh web: http://127.0.0.1:<port> after port is ready. Whether other layers (like desktop or external supervisor) open the browser is outside this bundle's scope.

Q: Why is --host 0.0.0.0 rejected?

A: The bundle currently intentionally doesn't support binding to all interfaces (will report usage error and exit before activation), because this would expose remote code execution capabilities to the network. Please use 127.0.0.1 or LAN trust host mode.

Q: What to do when "frontend dist not built" is reported?

A: This means the repository hasn't built the frontend dist. This bundle treats dist path as internal workspace knowledge, requiring pnpm run build to be executed in the repository root first, then start dsh --profile web.

Q: What is the DSH_WEB_URL variable for?

A: The bundle registers a bash-visible runtime variable DSH_WEB_URL, resolved from the currently listening local URL on each invocation. Models and scripts can use it to locate the current GUI.

Q: Why are some shared tools/toolbars with dsh-base disabled?

A: Web moves the agent plane (tool-bash, tool-pwsh, tool-fs, tool-skill, tool-subagent, etc.) to session-level agent presets; the host plane only keeps registry and services, so networked agents are assembled by their respective presets.

Q: HMR doesn't seem to be working?

A: The hmr line in cordis.patch.yml is currently disabled with a TODO: re-enable after Web-side reload lifecycle testing is complete; client plugin hot reload needs to配合 pnpm run dev:web watcher to trigger.

Getting Started Difficulty

Beginner — install once, run pnpm run build and dsh --profile web to see the interface in browser; no required configuration other than --host / --port / --trusted-host.

Known Issues & Limitations

  • Frontend dist must be built: The require.resolve for dist reports error during activation with build hints; no fallback path to serve directly from source (README.md:25)
  • lanAddresses is a startup snapshot: Network interface changes after startup won't re-announce; printed LAN URL always matches configured trust fence (README.md:26)
  • --host 0.0.0.0 is intentionally rejected: CLI treats "bind all interfaces" as a security risk and exits during parsing without publishing webStartup service (src/startup.ts:69-71)
  • hmr line is disabled: Marked with TODO in cordis.patch.yml, to be re-enabled after Web-side reload lifecycle testing completes (cordis.patch.yml:21-23)
  • DSH_TOOLS_MODE is a temporary workaround: The entire dsh process's tools mode (native|code|both) is switched via environment variable, to be removed after Web UI can select by session (cordis.patch.yml:36-41)

Read the usage guide →

Install steps, key points, FAQ and compatibility for this plugin — auto-derived from indexed fields.

Listing badge

Listed on deepseek-plugin.org
[![Listed on deepseek-plugin.org](https://img.shields.io/badge/listed_on-deepseek--plugin.org-007EC6)](https://deepseek-plugin.org/plugins/op7418/pilot-harness/packages/bundle/web-app)

Paste this markdown into your GitHub README to link back to this listing. The badge only states the listing — not a security endorsement.

← Back to plugin directory