If your point is that token should be a must with no exceptions then fine by me. Otherwise nothing is foolproof ( but in my opinion it's very difficult to spoof ip address of some other machine which no one but you even knows it.) Besides in case no token was used for login limitation should be...