I think I understand the difference between tokens and session ids.
But it seems to me that it has a major security issue so I've probably misunderstood something :
If someone steals my token or my session id then he can pretend to be me, right? Some XSS attack, or some F12 on my friend's computer is enough to see the info, right?