
5 JWT mistakes I see in production: → `alg: none` tokens accepted → RS256 key as HS256 secret (CVE-2015-9235) → No exp/aud validation → Refresh tokens that never expire → Credentials in localStorage Fix: explicit alg, httpOnly cookies, PKCE for OAuth.
Post summary
Highlights common JWT misconfigurations, cites CVE-2015-9235, and offers mitigation steps like explicit algorithm enforcement, httpOnly cookies, and PKCE for OAuth.
