dsh-session-upload
iceriverlin/dsh-session-upload
Composer attach button for DSH Web: multi-file picks become inline draft capsules, files are stored under the workspace uploads root with an auto-extracted UTF-8 .txt sidecar (txt/docx/xlsx/pptx/zip/odt, zero dependencies), and sent messages carry only the file name — never a raw path.
설치
dsh plugin --profile web add github:iceriverlin/dsh-session-uploadREADME
@iceriverlin/dsh-session-upload
Attach files to a DeepSeek Harness (DSH) conversation and make them readable by any agent out of the box.
- 📎 button in the composer tool row → multi-file picker.
- Uploaded files are stored under an uploads root with sanitized,
timestamped names — and an auto-extracted UTF-8
.txtsidecar is written next to each file whose content can be extracted (plain text copied through; docx / xlsx / pptx / zip / odt extracted with a built-in zero-dependency reader). No agent-side parsing libraries needed for those formats. - Each upload inserts an inline capsule at the end of the draft (native
conversation reference). Sending serializes to a compact
📎 <file name>text — full paths never enter the chat. - Capsules clear with the draft after sending.
Tested on DeepSeek Harness Web 0.1.1-rc.2 (host webServer exact route +
conversation.input.* slots + draft-reference pipeline). Newer dsh trains may
need a compatibility pass.
Install
dsh plugin --profile web add @iceriverlin/dsh-session-upload
dsh web
Local development (this repo):
dsh plugin --profile web add file:C:/path/to/upload-plugin
dsh web
Configure the uploads root (important)
The agent must be able to read the stored files, so pin the root to a directory
inside your DSH workspace. Patch the profile (profiles/web/cordis.patch.yml):
- id: session-upload
name: '@iceriverlin/dsh-session-upload'
inject: [webServer]
config:
root: 'C:/your/workspace/uploads' # ← absolute, agent-readable
Defaults when not configured: maxBytes = 50 MB,
path = /api/dsh-upload/v1/put, root = <dsh web cwd>/uploads — always set
root explicitly (the web server's cwd may not be your workspace).
Agent protocol
See AGENTS.md: a user message with 📎 <name> means the file is
stored under the uploads root as timestamp[-<SSS>]-<name> (match by suffix);
prefer the .txt sidecar when present.
Format matrix
| Upload | .txt sidecar | Notes |
|---|---|---|
| txt/md/json/csv/log/code | ✅ | content copied |
| docx/xlsx/pptx/zip/odt | ✅ | zip-family extraction, no deps |
| legacy .xls | ❌ | binary OLE — needs extra tooling (SheetJS) |
| ❌ | no built-in PDF sidecar; read side: pdf-parse / vision | |
| images/binaries | ❌ | original preserved (images: use your vision options) |
Remove
dsh plugin --profile web remove @iceriverlin/dsh-session-upload
dsh web
Uploaded files under the uploads root are not removed by uninstall.
Security notes
- Files stay local; nothing is forwarded anywhere.
- Filenames are sanitized (path separators, control chars, leading/trailing
dots, Windows reserved device names) with the extension preserved when a
long name is truncated, and namespaced with a
yyyyMMdd-HHmmss[-SSS]timestamp; no path traversal through the name, no same-second overwrite. - Archive text extraction is guarded against zip bombs (entry count and per-member size caps) and honors UTF-8 / UTF-16 BOMs.
- The route binds to the same
webServeras the GUI (loopback by default), answers onlyPOSTwith a non-empty body under the size cap. - Third-party code runs with host permissions: review before use. MIT licensed.