Eleven web findings. One commit, since they share the stylesheet and the layout.
Decisions taken on the way in, each reversible in a line:
- The settings grid puts the control and Save at the right edge, with a 14rem floor on the label column. Without the floor the control column claims its full 28rem and the hints wrap a word to a line — visible on the merge-gates rows before the floor went in.
- The profile's inactive tabs underline in =--line=, not =--faint=. At 2px =--faint= is invisible against the canvas in both schemes, so it is not a track.
- Tree icons are folder and file only. Per-filetype icons need an extension-to-glyph map and colour the glyphs by filetype, which the two accents are not for. Left for later.
- =/admin/users= renders the disabled Promote with an inert twin of the confirm input, so the cell matches the shape of the rows that have one. Note an admin row already carries two boxes with the same placeholder, one per action, so this follows the existing pattern rather than introducing it.
- Log out as a link retires the rail-foot button check in =TestRailIconsAreLabelled=. The loop above it matches an == wherever it sits, so the rule still holds for the foot; what replaces the deleted block asserts the foot holds a control at all, which the loop alone would not catch.
Verified on a local instance at both widths and in both schemes: =/krz/gitbay=, =/search= for a repo hit and an issue hit, =/settings= with three addresses (one unverified), =/krz/gitbay/settings=, =/admin/users= with a pending account, =/cmc=, =/logout=, and the More menu at 375px.
=go build=, =go vet= and =go test ./internal/web/... ./internal/httpd/...= green. =TestWebAccounts= green locally, which covers the new assertion that =GET /logout= renders and leaves the session alone. The rest of the e2e suite is CI's.
Closes #247