|
|
|
|
|
by drivebycomment
2217 days ago
|
|
The one case (and about the only case) I can think of where they can claim above is: If they have a log of all JWTs issued that records which user requested and which email in JWT, then they can retroactively check if they issued any (user, email) pair that they shouldn't have.
Then they can assert that there was no misuse, if they only found this researcher's attempt. |
|