.NET WebAPI centralized Authorization
In .NET WebAPI, I’ve created a way to have all of the authorization rules in a central location, rather than scattered throughout controllers. I’m curious why this centralization isn’t done more often; are there repercussions/security concerns?