# Wrap Custom Service Methods In The Operation Executor

Makes permissions and audit actually run on a custom service method instead of only appearing to.

Follow these project instructions.
# Wrap Custom Service Methods In The Operation Executor

Makes permissions and audit actually run on a custom service method instead of only appearing to.

Version: `1.0.0`

An operation attribute is metadata. On its own it enforces nothing. What applies permissions, writes the audit record, captures the actor and request context and measures duration is the service operation executor, and it only does that for calls routed through it.

So a custom method has two parts. Move the real body into a private core method, then make the public method the attributed wrapper that calls the executor and passes the core method as the delegate. Supply the execution options the record needs - tenant id and entity id when you have them, before and after snapshots when the change is worth reconstructing, an explicit permission or audit action name when the convention-derived one would be wrong.

Both outcomes are recorded: the executor writes the audit entry on success and on failure, then rethrows, so a failed attempt is as visible as a successful one.

Two things silently switch it all off. If no authorizer is registered, the permission check and the tenant demand are skipped entirely. And a method attributed but never routed through the executor is indistinguishable from an unprotected one at runtime - it compiles, it runs, and nothing is checked.

#### Constraints
- Do not assume a permission check ran because an attribute is present.
- Do not wrap private helpers - wrap the public method that callers reach.
- Never add an operation or permission attribute to a method that is not routed through the executor.

#### Verification
- A failed call leaves an audit record, not just a successful one
- An unauthorized caller is refused, proven by a test rather than by reading the attribute
- The attributed public method calls the executor and delegates to a private core method
