Files
dsh-lan-access/cordis.patch.yml
T
sutong a5f51a029f refactor: 包名改为 @wishesl/dsh-lan-access
与 GitHub 仓库归属 wishedl 对齐(原 @sutong 不是发布身份,npm 发布会 403)。
同时把包名改为单一来源:scripts/build-client.mjs 与 scripts/test-client.mjs
都从 package.json 读取,避免产物 id 与清单漂移。LICENSE 版权主体同步为 wishesl。
顺带修正 src/panel.js 里「Plugins 内页」的过时注释(面板早已是 Settings 顶层入口)。
2026-09-27 04:11:15 +08:00

53 lines
2.9 KiB
YAML

# @wishesl/dsh-lan-access — bundle patch.
#
# The LAN listener itself overrides no shipped row: it is a separate socket that
# forwards to the loopback web server, so the official webserver bind, the
# connection trust fence, and the launch token stay untouched, and disabling
# this bundle cannot break the loopback Web UI.
#
# The overrides below are UI-facing and deliberate. Each is explained where it
# appears and can be removed on its own.
# ── the LAN listener ─────────────────────────────────────────────────────────
# An ordinary Cordis plugin activated by package name.
- insert:
- id: dsh-lan-access
name: '@wishesl/dsh-lan-access'
config:
# The official client derives its `isLoopback` topology fact from
# `location.hostname`, and the durable settings surface is loopback-only
# by that rule: on a LAN page the settings mirror stays in `memory` mode,
# so the Models/provider pages fail with "settings are unavailable in
# this browser" and the config-file action disappears.
#
# Declaring `ownsHost` for non-loopback pages restores those screens.
# A loopback page is left untouched, and the Host/Origin fence plus the
# launch-token login are unchanged, so this does not widen server-side
# authorization — but that settings UI reads and writes server settings,
# credentials included. Set this to false to keep the shipped posture.
ownsHostCompat: true
# ── pin the in-browser directory picker ──────────────────────────────────────
#
# "Add workspace" asks the directory-picker seam for a folder. Its chooser row
# resolves ONE backend at boot from host facts, and `native` requires "a
# loopback-only bind (an all-interfaces bind admits remote browsers no OS
# chooser can reach)" plus a servable display. This bundle keeps the official
# webserver on loopback by design, so a LAN deployment still resolves to
# `native` — and the OS dialog opens on the server, where the remote operator
# cannot see or reach it.
#
# Pinning the `browse` pair is the documented way to force an interaction
# ("pinning an interaction remains composing that pair directly instead of this
# row"), and that backend "serves remote clients the dialog backend cannot".
# The seam mounts exactly one backend per process, so this also applies to a
# local page: it trades the OS dialog for the in-page browser everywhere.
# Remove these three entries to get the adaptive choice back.
- id: directory-picker
disabled: true
- insert:
- id: directory-picker-browse
name: '@deepseek-ai/dsh-host-directory-picker-browse'
- id: ui-directory-picker-browse
name: '@deepseek-ai/dsh-client-ui-directory-picker-browse'