Date.parse() returns NaN for invalid date strings. Previously, a grant
with expiresAt set to a malformed value (e.g. 'invalid') would pass the
expiry check (NaN > Date.now() === false, but the falsy NaN would skip
the check due to how the condition was written—or more precisely, would
evaluate incorrectly).
Now, if expiresAt is present but cannot be parsed, the grant is treated
as expired/invalid rather than silently allowing access.