Skip to content

Send temporal-namespace header from ActivityClient - #3138

Open
Sebruck wants to merge 1 commit into
temporalio:mainfrom
Sebruck:fix/activity-client-namespace-header
Open

Sebruck wants to merge 1 commit into
temporalio:mainfrom
Sebruck:fix/activity-client-namespace-header

Conversation

@Sebruck

@Sebruck Sebruck commented Oct 9, 2026

Copy link
Copy Markdown

What was changed

ActivityClientImpl now wraps its WorkflowServiceStubs in NamespaceInjectWorkflowServiceStubs, like WorkflowClientInternalImpl, ScheduleClientImpl and NexusClientImpl already do.

Why?

Without the temporal-namespace header, Standalone Activity calls (StartActivityExecution and the rest of the ActivityClient API) are rejected by Temporal Cloud for API-key authentication with PERMISSION_DENIED: Request unauthorized. Workflow starts through the same stubs and key work. We hit this in production use against Temporal Cloud and currently work around it by wrapping the stubs ourselves.

How was this tested

Added AuthorizationTokenTest.activityClientRequestsShouldHaveANamespace, which records the outgoing headers of StartActivityExecution. It fails without the change (expected:<default> but was:<null>) and passes with it.

WorkflowClient, ScheduleClient and NexusClient wrap their service stubs in NamespaceInjectWorkflowServiceStubs so every call carries the temporal-namespace header. ActivityClient did not, so Standalone Activity calls such as StartActivityExecution went out without it, and Temporal Cloud rejects them for API-key authentication with PERMISSION_DENIED: Request unauthorized.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@Sebruck
Sebruck requested a review from a team as a code owner October 9, 2026 12:59
@CLAassistant

Copy link
Copy Markdown

CLA assistant check
Thank you for your submission! We really appreciate it. Like many open source projects, we ask that you sign our Contributor License Agreement before we can accept your contribution.


Sebastian Bruckner seems not to be a GitHub user. You need a GitHub account to be able to sign the CLA. If you have already a GitHub account, please add the email address used for this commit to your account.
You have signed the CLA already but the status is still pending? Let us recheck it.

@Sebruck

Sebruck commented Oct 9, 2026

Copy link
Copy Markdown
Author

Just signed the CLA

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants