How do you handle logouts?
This reduces the necessary database roundtrips, while still supporting a logout flow.
For this to be exploitable, you'll have to jump several other hoops, like accessing localStorage of another application, for example.
No additional checks are performed on the back-end to verify whether the token has been revoked as that would reintroduce a round trip to the database you're trying to avoid in the first place.