An issue exists in Mattermost Server prior to 3.0.2. The purposes of a session ID and a Session Token were mishandled.
mattermost mattermost server