Might deviate quite a bit from fubu on this one. What if you had a convention that looked for methods called Authorize() : bool on the http handler classes that would be called inside the generated handler method. Should be able to take in arguments and even the input type.
Another recipe for declaring what claims the endpoint has to have?