Use case:
User logs in via oauth/authenticate
User logs out via accounts/end_session.  Cookies on my site containing
access tokens are cleared.
Same user logs back in later (in the same browser session) with

However, this last step produces a 403 forbidden: server understood
request but refuses to fulfill it.

Any ideas?  This should be a fairly basic use case...

