JWT tokens should be invalidated on the server after logout (A1) · Issue #544 · OWASP/Top10
... there's definitively an explanation needed or a better phrasing. Otherwise people read this and start implement blacklists denylists 🤦🏼 And: Metadata manipulation, such as replaying or tamperin...