Did any of the popular websites implemented insecure JWT handling in the past? I came across loads of tutorials on how to make it secure, but no writeups or post-mortem articles from actual companies.