server: replace global CSRF allowlist with per-route posture helpers
exorcise: B15b routes/pages/ + root routes doc comments
Restructure into monorepo