JWT Security Pitfalls: alg:none, Weak Secrets, and Missing Validation