Rows still open from the rc.13 manual-test review.
- TS2: docs/operating.md:100 says the HyperDX page never hands out the ClickHouse password, but operating.md:143 says NEXT_PUBLIC_* inlines it. Verify against the fork's bundle and delete the false statement.
- TS3: config/proxy/hyperdx.yaml:59 dropped the X-OIDC-* overwrite with nothing replacing it, so in header-dev a client on :8090/:8000 can assert its own identity. Add request_headers_to_remove for both headers on both listeners.
- TS9: scripts/_common.py:222 LOOPBACK_ORIGINS misses http://[::1] and http://0.0.0.0. Add them.
- TS10: docker-compose.yml:1088 interpolates DFE_EXTERNAL_ORIGIN into the CSP list unescaped, so a semicolon rewrites the policy. Validate the shape (scheme://host[:port]) in the make guard.
- TS12: docs/operating.md:97 still says the engine API answers unauthenticated on :3000, contradicting the file's own opening line and the engine. Fix the sentence.
- CD5: scripts/test_source.py _ui_origin returns the external origin regardless of bind scope, overriding DFE_POST_HOST and adopting an https scheme nothing serves. Keep DFE_POST_HOST ahead and reject a non-http origin.
- CD7: Makefile:21 and scripts/_common.py:244 disagree on a trailing slash, so http://localhost/ passes make and renders http://localhost/:3000. Give both one shared normaliser.
From the 2026-09-14 review of the rc.13 merges; rc.14.
Rows still open from the rc.13 manual-test review.
From the 2026-09-14 review of the rc.13 merges; rc.14.