doesn't this only protect against MITM attacks?
The premise of Session-Lock and DBSC is that even if the token gets stolen, it would not be useful to the attacker because the server would reject it if it doesn't have the correct signature that's generated using a private key that should only exist on the legitimate device. This private key has to be difficult or borderline impossible for the attacker to exfiltrate, unlike the session token.
This library adds more defense-in-depth, making it harder to attack sessions, but not impossible.