The first parity slice of #35: a maintainer can now complete the triage/review/merge loop in a browser.
Web actions dispatch the same control commands as the CLI — merge gates, review rules, and audit entries have one implementation, and SSHOnly commands (secrets, tokens, session minting) are refused on the web by construction.
- Review verdicts, merge with a strategy choice, and close in the aside, gated on write access
- Resolve and reopen review threads on the diff view
- Refusals redirect back with the command's own message, so a blocked merge explains which gate stopped it
e2e drives the whole loop through the browser: approve, a merge refused by the unresolved-thread gate, resolve, merge, and a reader refused. The wiki gains a Parity page tracking what each surface can do.
Ref #35