Comment on Self-Signed JWTsparentComments−motorest1yI did, and xss and session sniffing listed on the OWASP web page, would be prevented by following OAuth flows.OWASP's page lists 3 more examples which it seems you omitted for some reason.
Comments
OWASP's page lists 3 more examples which it seems you omitted for some reason.