A real incident from the finance app I build solo. The security design

was textbook. That's exactly why it bit me.

The textbook setup

Short-lived access token, long-lived rotating refresh token. Every

time the client refreshes: