Files
deepseek-harness/packages/host
Yichen Jiang c4c2355b50 fix(host): harden skill.invoke at the enforcement boundary
Review fixes: recheck isUserInvocable on the loaded definition (list and
get collect independently, so a provider change between them could swap in
a user-disabled body — the skill-tool execute template's second check);
thread the carrier signal through the lookup and refuse an abandoned
caller's turn as cancelled; fold lookup/loader failures into the
structured internal error the list face already uses; refuse cwd-less
sessions with the skill.list stance; and reject blank trailing text at the
wire schema instead of relying on client trimming.
2026-08-08 11:30:14 +08:00
..

host/ — web-GUI host half

English | 中文

The host side of the dsh web GUI: the API gateway every client shape shares, and the plain HTTP server it rides on. The browser side lives in client/; the composed application is apps/cli booting the dsh-base bundle serving apps/web. All product packages.

Package Role ctx key
apiproxy/ Shared host API gateway and wire contract ctx.apiProxy
webserver/ HTTP route carrier ctx.httpServer
frontend-static/ SPA dist server on the webserver fallback seat consumes ctx.httpServer
directory-picker/ Workspace-directory picking seam ctx.directoryPicker
directory-picker-native/ Native directory-picker backend and browser interaction registers ctx.directoryPicker
directory-picker-browse/ In-app directory-browser backend and interaction registers ctx.directoryPicker
directory-picker-auto/ Host-adaptive picker composition mounts a backend

apiproxy remains transport-independent; client/connection supplies the browser/HTTP carrier. Picker implementations replace one another behind the shared seam.