what if the token of jwt exists and the localStorage, is obtained through a xss attack, so that cross-site forgery requests can be made to send illegal requests to the server? Or you can add another ase request to token. I don"t know much about jwt just now.