If not logged in, redirect to a login page (resource) which upon success redirects back, e.g. GET login?next=desired_resource.
If logged in but not authorized to perform the action on the resource return 401.
That's it basically, isn't it? Also not trolling, challenge me if I'm missing something please.