> *command :*
> curl -H "Authorization: Bearer paste_jwt_token_here" 
> *result:*
> data shown without user credentials
> *expected result:*
> data not shown without user credentials
> any idea? or is it normal because from code above i've used 
> @auth.requires.login() even put the auth.is_logged_in() decorator?

Credentials are needed to get a token, not to use the token. There would be 
no point to the token if it required the credentials to be provided and 
verified along with it. The token itself serves as verification that the 
user is authorized.


