the bug is easily producible from : https://petstore.swagger.io/
- fill the value with token then authorize
- click logout
- click authorize without putting any token (leaving value empty), still able to authorize