mr create has always taken --source owner/name:branch; the web form offered
branches of the repo being viewed, so a contributor without write access had no
browser path to propose a change.
mrSources builds the picker: this repository's branches by name, plus the
branches of every fork of it the viewer can push to, as owner/name:branch.
Write on the fork is the filter — a contributor proposes from a fork they own,
and offering strangers' branches would just be noise. The command still resolves
and checks the source itself, so a posted source that is not a fork of the target
is refused there, not by the template. New store.ListForks.
TestMRFromForkWeb covers the flow end to end: bob forks, pushes, sees his
branch offered and opens the merge request; eve sees no branch she cannot push
to, and a non-fork source posted directly comes back as an error.
Forking itself is still CLI-only — filed separately, it is not in the matrix at all.
Closes #168