Tristan - The only thing I can think of is the user revokes their own tokens because they're concerned that it's been exposed. So they think they're stopping the 3rd party from using their token but the 3rd party can still use the token by modifying it slightly (until the token expires).
Yes, the typical concern would be an admin thinks the user's old tokens are revoked but they're still usable until they expire.
Tristan - The only thing I can think of is the user revokes their own tokens because they're concerned that it's been exposed. So they think they're stopping the 3rd party from using their token but the 3rd party can still use the token by modifying it slightly (until the token expires).
Yes, the typical concern would be an admin thinks the user's old tokens are revoked but they're still usable until they expire.