JWT authentication bypass via jku header injection