Continues the App.tsx slim-down. Two pieces move out of the monolith:
- `src/app/AppRoutes.tsx` — the route table and its 32 lazy page imports.
AppShell now renders `<AppRoutes />` inside the existing `<Suspense>`;
the `perfFlags.disableMainRouteContentMount` placeholder stays in
AppShell because that branch is a layout concern, not a routing one.
`useIsMobile()` moves inside AppRoutes so the `/now-playing` mobile
swap stays self-contained.
- `src/app/RequireAuth.tsx` — the 4-line auth guard, with a focused test
that covers all three reject paths (no login, no active server id,
empty server list) plus the happy path. MainApp imports it from the
new file instead of routing through the App.tsx re-export.
Side-cleanup of imports that B.2 had already orphaned in App.tsx
(`version`, `initAudioListeners`, `lazy`, `Routes`, `Route`, `Navigate`,
`MobilePlayerView`).
`App.tsx` 1308 → 1232 LOC. `AppShell` stays in App.tsx for Phase C.2.
Pre-PR check: PASS (frontend tests, tsc, coverage gates, prod build,
backend tests, clippy, backend coverage gates).