Review feedback on this PR. - The fallback list bypassed mergeColsRules, so col.TYPE was never set and every column reached the picker as char: char operators for numerics, and unquoted character values, which %mp_filtercheck rejects on the value list and on the submit alike. getcols.sas and the mock now emit TYPE in the client's vocabulary - char for C, num for N/DATE/DATETIME/TIME - and the cypress case no longer stops at selecting the variable: it sets a value, submits, and asserts the applied clause reads SITE_NAME = 'Bristol', so the quoting is the assertion. - The temporal exclusion is dropped, matching getdata.sas and viewdata.sas, whose cols payloads include those columns - the drop is on the data, not on the cols. The mock's getdata.js cols had the same divergence and is aligned; it keeps the exclusion for the rows. That also removes the SAS/mock disagreement on the excluded set, since there is no set. - client/.npmrc added with ignore-scripts and save-exact (plus legacy-peer-deps and fund, matching the root), so a local `cd client && npm i` is guarded the way the CI's is. Verified against the running mock: for MPE_CONFIG (TXTEMPORAL) getcols returns TX_FROM/TX_TO with TYPE=num and DDTYPE=DATETIME, the char columns as TYPE=char, and editors/getdata returns cols including both temporal columns while the rows still exclude them. row-cell-limits.cy.ts is 5/5.