I have a thin MVC client and a heavy Web API project in the same solution. Ive secured the MVC client. Since the client API is in the same solution, can i get away with