You can test by changing the server ACCESS\_TOKEN\_SECRET this will invalidate the token you have and should display a “remotely logged out” toast and then configure as if you aren’t logged in.
This should also generate a hacking report for us. Just log the IP, user credential, user if any, etc.