Skip to main content

dsh-web-ui/packages/dsh-plugin-manager

5.1kStars310Forks49Issues5Watchers

The Plugin Management tab in DSH web version supports npm/git installation, enable/disable toggles, conflict rollback, and failed repair session handling.

Evidence5/5methodologySourceInstallMaintenanceDSH versionSecurity scan
Machine-auditedInstall commandRepo verifieddsh-plugin topicLicenseREADMEAI wiki

ⓘ This plugin is a sub-package of the zhu1090093659/dsh-web-ui monorepo — stars and activity count the whole repository.

Language
TypeScript
License
Apache-2.0
Branch
dev
deepseek-harnessdshdsh-pluginweb-ui

Install

cmdweb profile
$ dsh plugin --profile web add @linxin666/dsh-client-ui-plugin-manager

Run the command above in your terminal to install this plugin via the dsh CLI. You can switch Profile in the top-right corner. New to dsh? Read the beginner tutorial

Install via your agent

Install the DeepSeek Harness plugin zhu1090093659/dsh-web-ui/packages/dsh-plugin-manager for me: review the repository at https://github.com/zhu1090093659/dsh-web first, then run the install command and verify the plugin loads successfully.

Paste this instruction to the DSH Web GUI assistant — it will install and verify for you.

One-Sentence Positioning

Adds a "Plugin Management" tab to the "Plugins" section of the DSH web settings page, allowing you to install new plugins from npm or git, enable/disable installed plugins (effective on next restart), check for updates and uninstall. Installation conflicts can be one-click reverted or handed to the Agent for fixing. It lets you manage plugins without returning to the command line.

Core Capabilities

  • Appends a "Plugin Management" tab to the official "Plugins" settings section (parallel to the official installer Tab), and exposes the same interaction entry as a pluginManager cordis service for sibling plugins to call.
  • Installs plugins from npm package names or git repository URLs, continuously returning progress during installation (fetch/download/extract/write phases), git source installations run as background tasks and may take several minutes.
  • Lists installed user plugins, provides "effective on next restart" enable toggle, supports update checking (npm source goes through registry), one-click update and uninstall.
  • Shows actual changes during each install/uninstall (product line or profile line diffs), can be one-click reverted; each conflict has a "Let Agent Fix" button that automatically initiates a repair session with the workspace in the plugin root directory.
  • Official runtime includes startup failure ring: each crashed plugin gives "Let Agent Fix" (failure details as seed) + "Copy Error" two buttons; npm runtime has no failure ring, only installation errors themselves carry repair handoff.
  • Shows host's safe mode banner and "Restore Normal Mode" operation; takes effect immediately on official runtime, takes effect after next manual restart on npm runtime.

Technical Implementation

  • Language: TypeScript (React browser side + Node host side + pure logic layer shared by both sides)
  • Key Dependencies: @deepseek-ai/cordis (plugin framework + service injection), @deepseek-ai/dsh-host-webserver (register gateway routes), @deepseek-ai/dsh-client-runtime (browser-side workspace/session injection), yaml (profile patch and package.json read/write parsing)
  • Architecture Pattern: Host/browser dual-half structure + dual-channel write. Host half inserts into web profile via profile bundle layer through cordis.patch.yml,承担 src/host/gateway.ts 描述的 CLI 网关与 src/host/routes.ts 描述的 HTTP 路由; Browser half loads via package.json's dsh.client declaration, registers a Tab to settings.plugins.tab slot. Write channels are divided into two categories: runtimes with official installer service (DSHCode, 1.0.4 checkout version web) go through official /plugin-installer and /plugin-control loopback RPC; npm-published official web doesn't have these two channels, this package's host half mounts a loopback gate HTTP gateway, install/uninstall spawns official dsh plugin CLI as single writer, enable/disable writes profile's disabled override line. The two channels are completely transparent to callers (unified pluginManager face).
  • Entry Files: src/index.ts (host half), src/client/index.ts (browser half)

Use Cases

Suitable for users who use DSH web version as their daily workspace and don't want to frequently switch back to the command line: installing new plugins, disabling a problematic one, checking for npm updates, reverting a failed installation — all can be done by clicking in the settings page. Also suitable for "family bucket" type users: when other developers want to add an "Install/Uninstall button" to their plugins or subscribe to "plugin just installed" events, they can directly ctx.inject(['pluginManager']) to reuse this plugin's capabilities without having to interface with official RPC again.

Prerequisites & Compatibility

DependencyMinimum VersionDescription
DSH (@deepseek-ai/dsh-client-*)^0.1.0-rc.8Official SDK version locked through peer/devDependencies; package.json does not declare engines field
Node^22.19 or >=24Repository shared constraint; this package itself not explicitly declared in package.json
PlatformmacOS / Windows / LinuxOn Windows, npm-generated dsh.cmd is resolved to node.exe + in-package bin.js, avoiding cmd.exe secondary parameter parsing
Native ModulesNoneAll go through Node built-in modules (node:child_process / node:fs / node:http / node:path) and yaml pure JS package

Installation

dsh plugin --profile web add github:zhu1090093659/dsh-web-ui/packages/dsh-plugin-manager

Configuration

This plugin requires no additional configuration. The Tab does not carry a configuration namespace; enable/disable switches and installation action effective timing are determined by DSH's own restart mechanism (effective on web side after next manual restart).

FAQ

Q: Why can't I see the "Plugin Management" tab in settings after installation?

A: You need to restart dsh web first. Enable/disable switches and installation actions all take effect after the next manual restart; the web side has no in-shell restart capability.

Q: Can this tab be used when accessing the web page from LAN or remotely?

A: No. All gateway routes only accept local loopback requests (quadruple gate: socket address + Host header + same-origin marker), non-local access directly returns 403, same boundary as official installer Tab.

Q: What's the difference between installing from npm and from git repository?

A: Both go through official dsh plugin CLI, but git source requires cloning the repository, may take several minutes and run as background task, progress bar can be viewed in the list; dsh command must be findable in host process's PATH, otherwise gateway will reject.

Q: What if it crashes on next startup after installation?

A: Official runtime has "startup failure ring" under that plugin, you can click "Let Agent Fix" to one-click initiate repair session (workspace is plugin installation root), or click "Copy Error" to take the error message. npm runtime has no failure ring, only installation errors themselves carry repair handoff.

Q: What are the "conflicts" shown during installation? Can they be reverted?

A: Conflicts are the actual product lines or profile lines changed by this installation, can be one-click reverted to state before operation; if cannot revert or don't want to handle manually, each conflict can "Let Agent Fix" for AI automatic handling.

Q: How do other plugins call this plugin's capabilities?

A: Inject via cordis service name pluginManager: after ctx.inject(['pluginManager'], cb), read ctx.pluginManager, can get five methods: list / install / uninstall / status / onChange, onChange callback after each successful install/update/uninstall/enable change.

Q: Can enable/disable switches cause some plugins to never start again?

A: On npm runtime, enable/disable is implemented by writing disabled override line to profile's cordis.patch.yml, but this path is not as well-exercised by official desktop writer, recommend caution for those "family bucket aggregate packages mounted via patch line"; official runtime is not subject to this limitation.

Q: How to completely uninstall?

A: Just restart dsh web after using dsh plugin --profile web remove with corresponding package name. This plugin has no configuration namespace of its own, no need to clean up config files.

Learning Curve

Beginner — install and use, zero configuration; users only need to "click a few times in settings page" to complete plugin installation, enable/disable, update and uninstall, no command line operations needed.

Known Issues & Limitations

  • Local loopback only: LAN or remote browsers only show "local operation only" hint, gateway returns 403 for non-loopback requests, same boundary as official installer Tab.
  • No startup failure ring and safe mode on npm-published official web: these two interfaces degrade to empty, only installation errors provide repair handoff.
  • Enable/disable on npm runtime depends on disabled override line in cordis.patch.yml; this path is not as well-exercised as official desktop writer, and cannot use disabled to bypass loader's duplicate check for shared entry ids (loader deduplication doesn't recognize disabled, writing it will accidentally harm existing plugins).
  • No in-shell restart on web side: all changes take effect after next manual restart of dsh web.
  • Conflict detection during installation reports "what actually changed" (product lines in official mode; profile lines and bundle entries in gateway mode); duplicate insert-id on npm runtime automatically rolls back new plugin after installation, won't touch existing plugins.
  • Duplicate mount protection: official CLI's bundle reconciliation adds any dependency declaring dsh.bundle back to dsh.profile.bundles, including packages already mounted via patch line (like dsh-better-sidebar), will cause duplicate prefix route startup failure; gateway only strips "newly added and already mounted via patch line" entries after each CLI change succeeds, normal entries and user's original entries stay untouched.
  • Startup pre-check (--dump-config) only combines patch layer, doesn't import entries: can catch combination failures, can't catch import period failures — the latter still exposes during first real startup.
  • Upstream CLI residue: official CLI still goes through cmd.exe shell when forwarding to pnpm on Windows, this package cannot change it, mitigated within this repository through spec metacharacter validation (& | < >, quotes, backticks, control characters).

Read the usage guide →

Install steps, key points, FAQ and compatibility for this plugin — auto-derived from indexed fields.

Listing badge

Listed on deepseek-plugin.org
[![Listed on deepseek-plugin.org](https://img.shields.io/badge/listed_on-deepseek--plugin.org-007EC6)](https://deepseek-plugin.org/plugins/zhu1090093659/dsh-web-ui/packages/dsh-plugin-manager)

Paste this markdown into your GitHub README to link back to this listing. The badge only states the listing — not a security endorsement.

← Back to plugin directory