/* Inter (variable) — relative path so the CSS keeps working if the /static route prefix changes */
@font-face {
    font-family: 'Inter';
    src: url('../font/Inter.ttf') format('truetype');
    font-weight: 100 900;
    font-style: normal;
    font-display: swap;
}

/* Theme knobs — every page is built from these variables, so rebranding (font, button color, radius, …) happens here and nowhere else. */
:root {
    --font: 'Inter', system-ui, sans-serif;
    /* Tailwind v4 gray-50 */
    --color-gray-50: oklch(0.985 0.002 247.839);
    --background: var(--color-gray-50);
    --card: #fff;
    --primary: oklch(0.205 0 0);
    --primary-foreground: oklch(0.985 0 0);
    --foreground: oklch(0.145 0 0);
    --muted-foreground: oklch(0.556 0 0);
    --border: oklch(0.922 0 0);
    --input: oklch(0.922 0 0);
    --ring: oklch(0.87 0 0);
    --destructive: oklch(0.577 0.245 27.325);
    --accent: oklch(0.97 0 0);
    --surface: oklch(0.985 0 0);
    --radius: 0.5rem;
    /* Tailwind's rounded-md = radius - 2px (used by cms inputs/buttons) */
    --radius-md: calc(var(--radius) - 2px);
    --success: oklch(0.627 0.17 149.2);
}

* {
    box-sizing: border-box;
}

.hidden {
    display: none;
}

body {
    margin: 0;
    color: var(--foreground);
    font-family: var(--font);
    background: var(--background);
}

/* Centered single-card shell — every page (forms, status, error) renders inside it */
.auth-shell {
    min-height: 100vh;
    min-height: 100dvh;
    display: flex;
    flex-direction: column;
    align-items: center;
    justify-content: center;
    padding: 24px;
}

.auth-card {
    width: 100%;
    max-width: 420px;
    padding: 32px;
    background: var(--card);
    border: 1px solid var(--border);
    border-radius: calc(var(--radius) + 4px);
    box-shadow: 0 1px 2px 0 rgba(0, 0, 0, .05);
    animation: auth-rise .45s cubic-bezier(.16, 1, .3, 1) both;
    view-transition-name: auth-card;
}

@media (max-width: 480px) {
    .auth-card {
        padding: 24px;
    }
}

.auth-logo {
    margin-bottom: 24px;
    view-transition-name: auth-logo;
}

.auth-logo img {
    display: block;
    height: 28px;
    width: auto;
    /* the placeholder logo is white-on-transparent — render it dark so it is visible on the light page background; drop this for logos that already carry their own color */
    filter: brightness(0);
}

.auth-title {
    margin: 0 0 2px;
    font-size: 24px;
    font-weight: 700;
    letter-spacing: -.02em;
    text-align: center;
}

.auth-subtitle {
    margin: 0 0 24px;
    color: var(--muted-foreground);
    font-size: 14px;
    line-height: 20px;
    text-align: center;
}

/* 24px gap between field groups (Tailwind space-y-6) */
.auth-label {
    display: block;
    font-size: 14px;
    line-height: 1;
    font-weight: 500;
    margin-top: 24px;
}

/* first field group sits flush under the title/subtitle */
form > .auth-label:first-child {
    margin-top: 0;
}

/* field group whose label row carries an inline link (e.g. "Forgot password?") */
.auth-field {
    position: relative;
    margin-top: 24px;
}

.auth-field .auth-label {
    margin-top: 0;
}

/* sits in DOM after the input (tab order) but is rendered beside the label */
.auth-field-link {
    position: absolute;
    top: 0;
    right: 0;
    line-height: 1;
}

.auth-input {
    display: block;
    width: 100%;
    height: 36px;
    padding: 4px 12px;
    margin-top: 8px;
    border: 1px solid var(--input);
    border-radius: var(--radius-md);
    font-size: 14px;
    font-family: inherit;
    background: transparent;
    box-shadow: 0 1px 2px 0 rgba(0, 0, 0, .05);
}

.auth-input::placeholder {
    color: var(--muted-foreground);
}

.auth-input:focus {
    outline: none;
    border-color: var(--ring);
    box-shadow: 0 0 0 3px color-mix(in oklch, var(--ring) 50%, transparent);
}

.auth-input.has-error {
    border-color: var(--destructive);
}

/* read-only fields (e.g. the account email on the set-password page): visibly not editable, but still selectable and readable by screen readers */
.auth-input[readonly] {
    background: var(--accent);
    color: var(--muted-foreground);
    cursor: default;
}

.auth-input[readonly]:focus {
    border-color: var(--input);
    box-shadow: 0 1px 2px 0 rgba(0, 0, 0, .05);
}

.auth-error {
    color: var(--destructive);
    font-size: 14px;
    margin-top: 8px;
}

/* Code-entry boxes on the "check your email" page */
.auth-otp {
    display: flex;
    gap: 8px;
    margin-top: 8px;
}

.auth-otp-box {
    flex: 1;
    min-width: 0;
    height: 48px;
    padding: 0;
    text-align: center;
    font-size: 18px;
    font-weight: 600;
    text-transform: uppercase;
    border: 1px solid var(--input);
    border-radius: var(--radius-md);
    font-family: inherit;
    background: transparent;
    box-shadow: 0 1px 2px 0 rgba(0, 0, 0, .05);
}

.auth-otp-box:focus {
    outline: none;
    border-color: var(--ring);
    box-shadow: 0 0 0 3px color-mix(in oklch, var(--ring) 50%, transparent);
}

.auth-otp.has-error .auth-otp-box {
    border-color: var(--destructive);
}

/* TOTP enrollment QR code (mfa-setup) */
.auth-qr {
    display: block;
    margin: 24px auto;
}

/* Recovery codes shown once after enrollment/regeneration (mfa-recovery-codes) */
.auth-recovery-codes {
    list-style: none;
    margin: 0 0 24px;
    padding: 0;
    font-family: ui-monospace, monospace;
    font-size: 14px;
    line-height: 1.8;
    text-align: center;
}

/* also usable on <a> elements (e.g. "Go to sign in" on result pages), hence the link resets */
.auth-button {
    display: inline-flex;
    align-items: center;
    justify-content: center;
    gap: 8px;
    width: 100%;
    height: 40px;
    padding: 0 24px;
    margin-top: 24px;
    background: var(--primary);
    color: var(--primary-foreground);
    border: none;
    border-radius: var(--radius-md);
    font-size: 14px;
    font-weight: 500;
    font-family: inherit;
    line-height: 1;
    text-decoration: none;
    cursor: pointer;
}

.auth-button:hover {
    background: color-mix(in oklch, var(--primary) 90%, transparent);
}

.auth-button:disabled {
    opacity: .5;
    cursor: not-allowed;
}

/* "or" separator between the password form and SSO buttons (cms: h-px bg-border lines + muted text) */
.auth-divider {
    display: flex;
    align-items: center;
    gap: 16px;
    margin-top: 24px;
}

.auth-divider::before,
.auth-divider::after {
    content: '';
    flex: 1;
    height: 1px;
    background: var(--border);
}

.auth-divider span {
    color: var(--muted-foreground);
    font-size: 14px;
}

/* outline button (cms Button variant="outline") */
.auth-button-outline {
    background: var(--card);
    color: var(--foreground);
    border: 1px solid var(--input);
    box-shadow: 0 1px 2px 0 rgba(0, 0, 0, .05);
}

.auth-button-outline:hover {
    background: var(--accent);
}

.auth-provider-icon {
    width: 16px;
    height: 16px;
    flex-shrink: 0;
}

.auth-foot {
    margin-top: 16px;
    text-align: center;
    font-size: 14px;
    color: var(--muted-foreground);
}

.auth-link {
    color: var(--primary);
    font-size: 14px;
    text-decoration: none;
}

.auth-link:hover {
    opacity: .8;
}

/* a form that reads as a single line of text (e.g. "Didn't get the email? Resend") */
.auth-inline-form {
    display: inline;
}

/* button that renders as an inline link (e.g. the resend button, which must POST) */
.auth-link-button {
    padding: 0;
    border: none;
    background: none;
    cursor: pointer;
    font-family: inherit;
    font-size: 14px;
    color: var(--primary);
}

.auth-link-button:hover {
    opacity: .8;
}

/* countdown state while the resend is held back */
.auth-link-button:disabled {
    color: var(--muted-foreground);
    cursor: default;
    opacity: 1;
}

/* stacked foot rows (e.g. resend line above the back link) sit closer together than the first row sits under the form */
.auth-foot + .auth-foot {
    margin-top: 8px;
}

/* in-button loading indicator shown while the code submit is in flight */
.auth-spinner {
    width: 16px;
    height: 16px;
    border: 2px solid color-mix(in oklch, var(--primary-foreground) 35%, transparent);
    border-top-color: var(--primary-foreground);
    border-radius: 50%;
    animation: auth-spin .7s linear infinite;
}

@keyframes auth-spin {
    to {
        transform: rotate(360deg);
    }
}

/* spinner variant for outline buttons, where the primary-foreground tones would vanish on the light background */
.auth-button-outline .auth-spinner {
    border-color: color-mix(in oklch, var(--foreground) 25%, transparent);
    border-top-color: var(--foreground);
}

.auth-status-icon {
    width: 44px;
    height: 44px;
    margin: 0 auto 16px;
    display: flex;
    align-items: center;
    justify-content: center;
    border-radius: 50%;
    color: var(--success);
    background: color-mix(in oklch, var(--success) 12%, var(--card));
    box-shadow: 0 0 0 6px color-mix(in oklch, var(--success) 5%, transparent);
}

.auth-status-icon svg {
    width: 20px;
    height: 20px;
}

.auth-status-icon-error {
    color: var(--destructive);
    background: color-mix(in oklch, var(--destructive) 10%, var(--card));
    box-shadow: 0 0 0 6px color-mix(in oklch, var(--destructive) 5%, transparent);
}

.auth-status-icon-muted {
    color: var(--muted-foreground);
    background: var(--accent);
    box-shadow: 0 0 0 6px color-mix(in oklch, var(--muted-foreground) 5%, transparent);
}

/* pill showing who is signed in (the subtitle's bottom margin provides the gap above) */
.auth-identity {
    display: flex;
    align-items: center;
    gap: 8px;
    max-width: 100%;
    width: fit-content;
    margin-inline: auto;
    padding: 6px 14px;
    border: 1px solid var(--border);
    border-radius: 999px;
    background: var(--surface);
    font-size: 13px;
    color: var(--foreground);
}

.auth-identity svg {
    width: 14px;
    height: 14px;
    color: var(--muted-foreground);
    flex-shrink: 0;
}

/* min-width: 0 lets the nested spans ellipsis instead of stretching the pill past the card */
.auth-identity-text {
    display: flex;
    flex-direction: column;
    min-width: 0;
    line-height: 1.35;
}

.auth-identity span {
    overflow: hidden;
    text-overflow: ellipsis;
    white-space: nowrap;
}

.auth-identity-email {
    font-size: 12px;
    color: var(--muted-foreground);
}

/* an action directly following the subtitle (status pages) — the subtitle's bottom margin already provides the 24px gap;
   .auth-action marks button-only forms (logout) so forms with visible inputs keep the button margin */
.auth-subtitle + .auth-button,
.auth-subtitle + .auth-action > .auth-button {
    margin-top: 0;
}

/* subtle entrance on fresh loads */
@keyframes auth-rise {
    from {
        opacity: 0;
        transform: translateY(10px);
    }
}

@media (prefers-reduced-motion: reduce) {
    .auth-card {
        animation: none;
    }
}

/* Cross-document view transitions: navigations between the auth pages morph into each other instead of hard-reloading (SPA feel without
   any JS or fetch layer — works across form POST redirects too). Browsers without support simply fall back to normal navigation. */
@view-transition {
    navigation: auto;
}

@media (prefers-reduced-motion: reduce) {
    @view-transition {
        navigation: none;
    }
}

/* the entrance animation is for fresh loads — during a page-to-page transition the morph already does the work */
html:active-view-transition .auth-card {
    animation: none;
}
