AntiPattern
Miswired Crypto/Auth Boundaries
miswired-crypto-auth-boundaries
Validation, encryption, and key management responsibilities get mixed up—JWT secrets used by the signer also “validate,” AES lacks integrity/authentication, and secrets aren’t safely scoped—so tokens and ciphertext may be accepted or decrypted incorrectly.