I think Token Revoke when user logged out is necessary. Also Re-generate token / Override / Refresh token for more security