Hey Wetwiper, i like your Nickname :)
thanks for the review :-)
1. Yeah, I do understand the working of JWT and Signatures, it was made in a simpler format for naive first time users. There is no security flaw in that
2. Yeah, you are right in a way, but I have seen people do it in case of JWT, as they store the User-id there as well
3. Hahaha.. that's a DB lookup, you loose ;-)
4. I don't understand how multiple would work. Well, as for your "insecure methods" comment, I have a classic example of employees leaving the Tech team.
And as for Signing algorithm you can never say anything. A few years back MD5 was considered most secure and could not be broken and used in every Digital Signature. Now there are websites that generate the text based on the HASH value.. that is not using Rainbow tables. So, even salts in this case wont work :-|
I agree, that my review was biased (isn't everyone? :-o )