use jsonwebtoken::{Validation, decode}; pub fn verify_token(token: &str) -> bool { // BAD: Disable audience validation let mut validation = Validation::default(); validation.validate_aud = false; decode::(token, &key, &validation).is_ok() }