This also means an attacker can be running around with a compromised token for up to a half hour before they're stopped.
For this to be exploitable, you'll have to jump several other hoops, like accessing localStorage of another application, for example.