Files
deepseek-harness/packages/client
Yichen Jiang 2dd4b8e78d fix(host): pin model discovery to loopback and drop its unread wire field
llm.discoverModels was reachable from any declared trusted host. The
method takes a caller-supplied baseURL and makes the host issue a GET to
it, then reports the status or the parsed body — so on a LAN deployment
an anonymous caller had a probe for whatever the host can reach and the
browser cannot, plus a path that carries a draft credential. The
PRIVILEGED_METHODS doc already states the rule this broke: trustedHosts
is a DNS-rebinding fence, not authentication, so the configuration plane
stays loopback-same-origin. It is in that set now, asserted both against
the hand-built fence and over real HTTP beside the catalog reads that
deliberately stay reachable.

supportsDiscovery and listModelDiscoveryNamespaces are gone. The field
was required on the wire and read by nobody: its own contract said a
surface should offer the action "instead of naming an adapter family it
would have to hardcode", while the surface hardcodes llm-pi-ai in two
places and gates the button on whether there is anything to probe. Its
shape did not fit the second caller either — the create card has no row
to read a per-row field from. Keeping a required field alive for a
consumer that may never arrive costs every producer and fixture a value
nobody consults, which is exactly how the fixtures drifted. The registry
that fed it had no other production consumer, so registration and
disposal are now observed through the offer itself.

The Agent Note claimed the key is never logged, which the wire schema
beside it already contradicts, and predated both the provider field and
the catalog-answer path. The two new public types pointed at core.md
without a type-equiv block or manifest entry, so the generated service
catalog named documentation that did not exist.
2026-08-05 19:51:11 +08:00
..

client/ — web-GUI browser half

English | 中文

The browser side of the dsh web GUI: shell boot, browser-host communication, shared UI services, and feature plugins. Authoring rules live in AGENTS.md; the host half is host/. All except test-runtime are product packages named @deepseek-ai/dsh-client-<name>.

Package Purpose
web/ Boots the browser shell from the client entry graph.
modules/ Loads browser-side client modules.
web-react/ Connects the shell runtime to React rendering.
connection/ Maintains browser-host RPC communication and event delivery.
runtime/ Provides shared client services for sessions, workspaces, and UI composition.
hmr/ Refreshes client plugins during development.
locale/ Provides localization preferences and message dictionaries.
schema-form/ Provides schema-backed draft handling for settings editors.
test-runtime/ Provides shared repository test support for client feature packages.
ui-slots/ Defines how UI features register and compose extension slots.
ui-theme/ Applies the selected color theme.
ui-primitives/ Provides shared React controls, icons, and content renderers.
ui-layout/ Arranges the main application regions.
ui-sidebar/ Presents workspace and session navigation.
ui-workspace/ Provides workspace selection and creation surfaces.
ui-conversation/ Presents the active conversation and its input surface.
ui-goal/ Presents and manages the current goal.
ui-trajectory/ Presents alternate views of agent activity.
ui-command/ Provides session-aware command discovery and dispatch.
ui-slash/ Coordinates inline command and reference suggestions.
ui-skill/ Adds skill references to inline suggestions.
ui-subagent/ Provides subagent navigation, child transcript states, and inline references.
ui-model/ Provides model selection in conversation surfaces.
ui-permission/ Configures default permissions and switches the current session's access.
ui-plan/ Presents active plan-mode status and its exit control.
ui-question/ Presents interactive questions requested by the agent.
ui-settings/ Hosts the settings interface and its extension areas.
ui-settings-general/ Provides the general settings section.
ui-models/ Provides model-provider configuration and DeepSeek onboarding.

Each child reference owns its contract and detailed behavior. The slot system standard and web client architecture note own the cross-package composition and loading decisions.