Is setting JWT claim to requesting actor’s (i.e. the current user) webfinger value and then decrypting them a good way to check if actor A follows B?