Five findings from the #939 review, each reproduced before being fixed. **Configuration reads are as privileged as writes.** `settings.describe` returns every exposed namespace's configuration and `credentials.describe` reports whether an arbitrary environment-variable name is configured and from where — reconnaissance no anonymous caller should have. Both join PRIVILEGED_METHODS, so the whole configuration plane is loopback-only until real authentication exists; `trustedHosts` was never authentication. The model catalog stays reachable: it carries no endpoints or key state, and a LAN client's model picker legitimately needs it. Asserted over a real HTTP server, because the Host header a browser actually sends is what decides this. **The proxy serves only namespaces a registered model provider addresses.** The settings seam is general — any plugin may register one — but the Web configuration plane is the model-provider surface. Without the gate, every future `settings.register()` would silently become remotely readable and writable configuration. An unregistered namespace and an unexposed one answer identically, so no caller can enumerate the registry one probe at a time. **Path-addressed writes replace the redacted-document rebuild.** The editor reads the REDACTED descriptor, so rebuilding a section from it and replacing wholesale deleted every literal secret the wire never returned — reproduced as `{baseURL, reasoning}` in, stored `apiKey` gone out. `settings.mutate` applies set/unset ops to the section as it stands at the front of the seam's write queue, and the client names only fields it can see, so an unseen secret is untouched by construction rather than by care. P2s in the same pass: `llm/adapters-updated` now contains async listener rejections (an uncontained one escaped as unhandledRejection, contradicting the documented "observer failures are contained"); llm-deepseek's retry-policy swap uses the atomic `registration.replace` instead of dispose-then-register, which published `[]` then `["deepseek-official"]` so an observer saw the provider disappear and come back; and a transport rejection no longer strands the page in `loading` or a card in `busy`, with removal failures surfaced on the page banner instead of swallowed.
client/ — web-GUI browser half
English | 中文
The browser side of the dsh web GUI: shell kernel, module system, wire consumer, React-free object services, the slot system, and the ui-* feature-plugin roster. Authoring rules live in AGENTS.md; the host half is host/. All product packages, named @deepseek-ai/dsh-client-<name>.
| Package | Role | ctx key / slot |
|---|---|---|
web/ |
Shell kernel: AppWebEntry runs the two-stage boot over the host-pushed entry graph |
(boots the tree) |
modules/ |
Client module system: browser peer of Node's ESM loader as a lazy CJS table under the vendored cordis Loader | (module face) |
web-react/ |
Shell-side React glue: createSlotRenderer + SessionProvider render seats |
(renderer install) |
connection/ |
Wire consumer both ends: browser ctx.connection (shared api client + stream loop) and the node half mounting the /api route with its browser-trust fence |
ctx.connection |
runtime/ |
Client cordis boot and React-free object services: slots, Sessions, Workspaces, per-session bindings | ctx.slots ctx.sessions ctx.workspaces |
hmr/ |
Dev-only hot reload for fetch-arrival client plugins (--dev graphs) |
(dev entry) |
locale/ |
Browser locale preference (zh/en) plus the ns×locale dictionary registry |
ctx.locale |
ui-slots/ |
Slot registry pure core: SlotMap merging, single register API, the four-share props family |
(types + core) |
ui-theme/ |
Theme preference over the --dsw-* token stylesheets (light/dark/system) |
ctx.theme |
ui-primitives/ |
Pure React atoms: icons, Button/Pill/Menu/Modal/Input, markdown family | (component library) |
ui-layout/ |
Shell three-column AppFrame; declares sidebar / conversation / details / conversation.empty |
ctx.layout |
ui-sidebar/ |
Sidebar shell: Workspace/session rail, search, collapse; declares sidebar.workspaces |
(slot host) |
ui-workspace/ |
Shared Workspace picker: browser region + hero picker over the same creation flow | (fills sidebar.workspaces, conversation.hero.workspace) |
ui-conversation/ |
Conversation domain: skeleton, chat view, input dock, per-tool row slots | (slot host) |
ui-trajectory/ |
Trajectory/Waterfall view tabs; the minimal pure-consumer plugin exemplar | (fills conversation.view) |
ui-command/ |
Command surface: session-keyed directory cache, / source, three-kind dispatch |
ctx.command |
ui-slash/ |
Input trigger pipeline: / and @ detection, grouped candidate menu, source roster |
ctx.slash |
ui-skill/ |
/-trigger skill reference source over the skill.list RPC |
(registers into ctx.slash) |
ui-subagent/ |
@-trigger subagent reference source over the sessions snapshot |
(registers into ctx.slash) |
ui-model/ |
Model selection: /model popupSelect + the composer model seat over ModelService |
ctx.models |
ui-question/ |
Web ask_user_question: host half mounts the tool, browser half fills the composer seat |
(fills conversation.composer) |
ui-settings/ |
Settings shell: trigger chrome + modal panel; declares the settings.* slots |
(slot host) |
ui-settings-general/ |
Settings ownerless copy: chrome content + General section skeleton | (fills settings.*) |
ui-models/ |
Models settings nav entry (content column lands in a later phase) | (fills settings.section) |
Feature UI composes only through the slot system (ctx.slots.register) — the slot system standard is the definitive model; the web client architecture note owns the loading chain and object layer.