Zenjibad
dsh-lan-uuid-fix
dsh bundle: polyfill crypto.randomUUID on insecure origins so the DeepSeek Harness Web UI works over plain-HTTP LAN
- Stars
- 0
- Language
- JavaScript
- Created
- Aug 14, 2026
- Updated
- Aug 14, 2026
Introduction
dsh-lan-uuid-fix
A DeepSeek Harness (dsh) plugin bundle that makes the Web UI work over plain-HTTP LAN addresses.
The bug it fixes
The web client's mintRpcId() calls crypto.randomUUID(). Browsers only expose that API in secure contexts — HTTPS, or loopback. A plain-HTTP LAN origin like http://192.168.1.66:3080 is not secure, so crypto.randomUUID is undefined:
| Page origin | Secure context | crypto.randomUUID |
|---|---|---|
http://127.0.0.1:3080 | yes | function |
http://192.168.1.66:3080 | no | undefined |
When it's missing, every unary RPC (host.describe, workspace.list, session.list, ...) throws TypeError: crypto.randomUUID is not a function, the connection generation aborts, the WebSocket streams are killed mid-handshake, and the UI never loads the session/workspace baseline — the workspace browser just shows "No sessions yet" and the console loops connection lost, retry #N.
crypto.getRandomValues is available on insecure origins, so a UUID-v4 backfill fixes it without HTTPS.
How it works
A host plugin registers an index tap on ctx.webServer (the webserver's html-transform hook, applied to every served index.html). The tap injects an inline polyfill that defines crypto.randomUUID from crypto.getRandomValues when missing, before the app bundles execute. Loopback and HTTPS pages are untouched — the polyfill only activates when the API is absent.
Install
dsh plugin --profile web add https://github.com/Zenjibad/dsh-lan-uuid-fix
The profile patch layer is applied live (HMR), so a running dsh web picks it up without a restart. Hard-refresh the page on the remote device afterwards.
The plugin adds one row, lan-uuid-fix, which injects webServer and taps the index. If your profile previously added this row with a local file path, remove that row before installing the bundle to avoid a duplicate id.
Verify
From the machine serving dsh, or any LAN client:
curl -s http://<host>:3080/ | grep randomUUID # polyfill present
The workspace browser should list sessions instead of "No sessions yet", and the browser console should show no connection lost retry loop.