TL;DR
Dont trust user suppplied data, donĀ“t screw up your jwt validation.
Understanding the application
The Ino Filemanager lets us, after registration, upload files and make them publicly available.
After registering a user and logging in, we observed that we were issued a JSON Web Token (JWT).
The