Why Decoding a JWT Is Not Verifying It (And How Security Bugs Slip Through)
Last Tuesday, a staging auth bug had three devs stumped for half an afternoon.
Nginx was spitting 401 Unauthorized. But the tester dumped their Bearer token into Chrome's DevTools console, ran JSON.pa
devomnitools.hashnode.dev6 min read