// Always strip inbound principal headers to prevent external callers from
// spoofing principal identity, regardless of whether the authorizer is enabled.
if a.authorizer != nil {
// Namespace is not available in the stream handshake (no initial request body).
ct := &CallTarget{