I\'m creating custom policies for a web api. I assumed that requiring a authenticated user in a policy would prevent other requirements to be ran. I know that adding multiple re