Applying a label worked from the web; the set itself was CLI-only.
/{owner}/{repo}/labels lists the labels with their colour and issue count,
linked from the issue list next to milestones. A writer gets a create form, a
colour field per row, and remove; each dispatches label set / label remove,
so validation and permissions stay in the command — a reader sees the set and no
controls, and a bad colour comes back as the command's own message.
TestLabelsWeb covers create, recolour, the rejected colour, remove unlinking
the issue, and the reader case. The page is in the private-repo isolation list.
Parity row and prose updated.
Closes #163