Really solid breakdown, especially the points about short-lived access tokens, httpOnly cookies, and avoiding sensitive data in JWT payloads. I also agree that many projects underestimate brute-force protection and frontend token handling until it becomes a problem later.
Interesting mention of PASETO too not something people bring up often, but definitely worth considering depending on the architecture and security requirements.