Curious about the 2. JWTs are signed via a secret key right? Couldn't the backend verify the signature and reject the token. I am pretty confident most JWT implementation does that automatically.
The dude just didn't think about that or looked into how JWTs work. Which I believe is even worse :<