Thanks, for the article. Always good to refresh the common pitfalls.
There is a RFC which also details the best practices for JWT: - JSON Web Token Best Current Practices: https://tools.ietf.org/html/rfc8725
On the similar topic, some more interesting RFCs / Drafts from IETF on OAuth: - OAuth 2.0 Threat Model and Security Considerations https://tools.ietf.org/html/rfc6819
- OAuth 2.0 for Browser-Based Apps - https://tools.ietf.org/html/draft-ietf-oauth-browser-based-a...