The noindex hiding outside the HTML
Check the page source as long as you like. Nothing in it opts this page out. The headers do.
The HTTP layer can carry rules too
An X-Robots-Tag header carries the same directives a robots meta tag carries. The difference is placement: it rides along in the HTTP response, not in the HTML document. Servers and CDNs reach for it on files that have no HTML head to work with, PDFs among them. The drawback: view the rendered markup and the tag is nowhere to be seen. That is how one sits unnoticed for months.
Why a crawler reads more than markup
Read only the HTML and this page looks indexable, because the markup never says otherwise. Catching a header-level rule takes a crawler that inspects the response headers on every single request. That check is the whole reason this page exists: it tests whether an audit reads headers or simply trusts the HTML.