Hardcoded secrets, unverified tokens, and other common JWT mistakes | Open Awesome