Please do not open a public issue for security problems. Use GitHub's private vulnerability reporting instead: open the Security tab of this repository and choose Report a vulnerability.
Include the affected component, steps to reproduce, and the impact you observed. You can expect an acknowledgement within a few days.
This project is a reference implementation intended for local use. Its default configuration contains development-only credentials and no authentication.