Never, ever use access tokens as proof of identity the way you are doing it. It makes you vulnerable to token substitution attacks. OAuth2 is not an authentication protocol.
https://oauth.net/articles/authentication/
DO NOT USE THIS in its current state. Stop upvoting this.