Isn't passing the session token in the query string insecure?
The payload of the requests will be encrypted (assuming HTTPS), but the urls are not. So I think you're opening the door to session hijacking in this way.
edit: I was wrong about this. The URL will be confidential in transit. Thanks for setting me straight.
I still think it is not a great design, but for different reasons: the url will be visible in your browser history and on the server side in the logs.