Try to return a redirect instead a 400 for "not logged in" state