Apply policy to pre-authenticated user

Well, maybe it would be easier to just let Tyk validate the JWT again. This isn’t necessary, but the overhead would probably be the same as using a custom javascript middleware :slight_smile: