You do not have permission to delete messages in this group
Copy link
Report message
Show original message
Either email addresses are anonymous for this group or you need the view member email addresses permission to view the original message
to Spring Security REST
If refresh_token stolen there is no way to prevent to login except by changing signature secret. jwt cannot be 100% stateless as needs to invalidate refresh_token after UserDatails change (such as password) in db