Yep, this alone is a borderline fatal flaw. The practice of sharing links, whether done intentionally or unintentionally through email forwarding, is pervasive and people won't stop to think about whether the url contains an embedded login token. This practice opens up a new class of vulnerabilities in the human error realm.
Now there could of course be ways around this like time/ip/geo pattern tracking, but that's no trivial enterprise.
Now there could of course be ways around this like time/ip/geo pattern tracking, but that's no trivial enterprise.