current user token still be validating with JWT in web api even though user signout from the client application (angujar js 1.x)