Without the ability defined, the user is still logged out, but then the deny_access check redirects to the login page. The re-login attempt would then fail anyway, with an error message, but let's fix the abilities and use the intended page.