reactive-resume
reactive-resume
A one-of-a-kind resume builder that keeps your privacy in mind. Completely secure, customizable, portable, open-source and free forever. Try it out today!
PROJECT TOPICS
INSTALL REFERENCE
dsh plugin --profile web add github:MerkurevSergei/dsh-notion-oauth-ui
该命令指向仓库当前默认分支;尚无绑定当前 commit 的完整验证结果。
PROJECT README
Connect Notion from the DeepSeek Harness GUI with OAuth 2.0 (authorization code + PKCE) — no Integration Token to copy, and no terminal required. Pages, databases and comments are reached through the official Notion MCP server.
client_id/secret to copy.dsh notion login for headless / CLI profiles.1. Install — open Plugins in the sidebar, then Add plugin, enter dsh-notion-oauth-ui and press Install.


2. Open Settings — the gear at the bottom of the sidebar, or Ctrl + ,.

3. Sign in — open Notion and press Login.

4. Approve — the browser opens the Notion consent page: pick a workspace, tick the I recognize and trust this URL checkbox, then press Continue.

5. Done — the page switches to Connected, and the mcp__notion__* tools become available.

On a headless or CLI-only profile the same flow runs from the terminal:
dsh plugin --profile <name> add dsh-notion-oauth-ui
dsh notion login
| Key | Default | Meaning |
|---|---|---|
mcpUrl |
https://mcp.notion.com/mcp |
Notion MCP server URL |
port |
53007 |
Local OAuth callback port (127.0.0.1) |
refreshLeadMs |
300000 (5 min) |
Refresh the token this far before it expires |
refreshRetryMs |
60000 (1 min) |
Retry interval when a refresh attempt fails |
/api/dsh-notion-oauth-ui/{status,login,logout}. Each route is pinned to one HTTP
method (GET /status, POST /login, POST /logout) and accepts only requests
whose remote address and Host are loopback and that are not Sec-Fetch-Site: cross-site. When an Origin is present it must be the app itself
(dsh-app://app) or the same host. The Desktop shell proxies renderer calls and
strips Origin/Sec-Fetch-Site, so an absent Origin is normal; the two POST
routes therefore additionally require Content-Type: application/json — not a
CORS-simple value, so a cross-site caller first needs a preflight that these
routes reject.state the
callback server verifies, and a 10-minute deadline on the callback. A malformed
or forged callback is answered with 400 and leaves the pending login running,
so a stray local request cannot kill a real authorization.mcpUrl must be https:// — the plugin refuses to load
otherwise. Discovery endpoints (authorization, token, registration) are read
from whatever the mcpUrl resource advertises, so keep it on a trusted origin.NOTION_OAUTH). That store is only as private as your
OS user account: tool processes run as the same user, so any plugin with
credentials access can read every stored secret (NOTION_OAUTH,
DEEPSEEK_API_KEY, …), not just its own. The token is never exposed to the
browser half, never returned by an HTTP route, and never written to logs.pnpm install # installs dev dependencies and builds lib/ via the prepare hook
pnpm run build # rebuilds lib/index.js (host) and lib/client.js (browser half)
lib/ is build output and is not committed; pnpm install and pnpm pack
regenerate it through the prepare script.
pnpm run typecheck checks the sources against the DSH host packages
(@deepseek-ai/*). DeepSeek Harness provides those at runtime, and their npm
publication is currently incomplete — some transitive packages are missing from
the registry — so typechecking needs an environment that supplies them. The
build itself has no such dependency.
MIT — see LICENSE.
Reuses code and design patterns from two MIT-licensed Notion plugins:
mingzeng21/dsh-notion (published as dsh-notion-mcp) — Copyright (c) 2026 mingzengzhengjy01/dsh-notion-connector — MIT per its package.jsonCLASSIFICATION EVIDENCE
系统优先读取 GitHub Topics,再与站内分类词典和词根规则比对。当前命中: mcp、oauth。