Source Admin stores configured database credentials in a local metadata database encrypted with APP_CONFIG_ENCRYPTION_KEY. Local admin passwords are stored as salted scrypt hashes.
The default npx source-admin flow is intended for local use on a trusted machine. For team or internet-exposed deployments, set strong NEXTAUTH_SECRET or AUTH_SECRET and APP_CONFIG_ENCRYPTION_KEY values, do not enable DEV_AUTH_BYPASS, and run the app behind a reverse proxy.
Please report security issues privately to the repository owner or through GitHub's private vulnerability reporting if it is enabled for the repository. Do not include live credentials, connection strings, or production payload data in public issues.