/* pages/auth.css — sign-in card, the user widget in the rail and role badges.
   Every colour is a token (tokens.css); lint_css.js reads this file. 2026-09-26: it carried 41 colour literals and a
   dark-theme block for a theme this app does not have, which is how a palette forks. Role badges carry white text,
   so each role colour is >= 4.5:1 (WCAG 2.2 AA). */
.auth-modal-overlay {
  position: fixed;
  inset: 0;
  background: rgba(var(--ink-rgb), 0.75);
  backdrop-filter: blur(8px);
  -webkit-backdrop-filter: blur(8px);
  display: flex;
  align-items: center;
  justify-content: center;
  z-index: 9999;
  animation: authFadeIn 0.2s ease-out;
}

@keyframes authFadeIn {
  from { opacity: 0; transform: scale(0.98); }
  to { opacity: 1; transform: scale(1); }
}

.auth-card {
  background: var(--surface);
  border: 1px solid var(--line);
  border-radius: var(--r-lg);
  width: 100%;
  max-width: 440px;
  padding: var(--sp-7);
  box-shadow: var(--sh-3);
  position: relative;
  color: var(--ink);
}

.auth-header {
  text-align: center;
  margin-bottom: var(--sp-6);
}

.auth-logo {
  width: 48px;
  height: 48px;
  background: linear-gradient(135deg, var(--brand-2) 0%, var(--brand-deep) 100%);
  color: var(--on-dark);
  border-radius: var(--r-md);
  display: inline-flex;
  align-items: center;
  justify-content: center;
  font-size: 24px;
  font-weight: 700;
  margin-bottom: var(--sp-3);
  box-shadow: 0 4px 12px rgba(var(--brand-rgb), 0.3);
}

.auth-header h2 {
  margin: 0 0 6px 0;
  font-size: var(--fs-xl);
  font-weight: 700;
  letter-spacing: -0.02em;
}

.auth-header p {
  margin: 0;
  color: var(--ink-muted);
  font-size: var(--fs-md);
}

.auth-form-group {
  margin-bottom: var(--sp-4);
}

.auth-form-group label {
  display: block;
  font-size: var(--fs-sm);
  font-weight: 600;
  text-transform: uppercase;
  letter-spacing: 0.05em;
  color: var(--ink-muted);
  margin-bottom: 6px;
}

.auth-input {
  width: 100%;
  padding: 10px 14px;
  border-radius: var(--r-sm);
  border: 1px solid var(--line-strong);
  background: var(--surface-2);
  font-size: 14px;
  color: inherit;
  box-sizing: border-box;
  transition: all var(--dur-fast) ease;
}

.auth-input:focus-visible,
.auth-input:focus {
  outline: 2px solid var(--info-strong);
  outline-offset: 1px;
  border-color: var(--info-strong);
  background: var(--surface);
}

.auth-btn-primary {
  width: 100%;
  padding: var(--sp-3);
  background: var(--brand);
  color: var(--on-dark);
  border: none;
  border-radius: var(--r-sm);
  font-size: 14px;
  font-weight: 600;
  cursor: pointer;
  transition: background var(--dur-fast) ease;
  margin-top: var(--sp-2);
}

.auth-btn-primary:hover {
  background: var(--brand-2);
}

.auth-btn-primary:focus-visible {
  outline: 2px solid var(--info-strong);
  outline-offset: 2px;
}

.auth-btn-primary:disabled {
  opacity: 0.6;
  cursor: not-allowed;
}

.auth-switch {
  margin-top: 18px;
  text-align: center;
  font-size: var(--fs-md);
  color: var(--ink-muted);
}

.auth-switch a {
  color: var(--info);
  font-weight: 600;
  text-decoration: underline;
  cursor: pointer;
}

.auth-alert {
  padding: 10px 14px;
  border-radius: var(--r-sm);
  font-size: var(--fs-md);
  margin-bottom: var(--sp-4);
  display: none;
}

.auth-alert.error {
  display: block;
  background: var(--danger-wash);
  border: 1px solid var(--danger-line);
  color: var(--danger);
}

.auth-alert.success {
  display: block;
  background: var(--ok-soft);
  border: 1px solid var(--ok-line);
  color: var(--ok);
}

/* User profile widget in the navigation rail. The rail is LIGHT (--rail): the widget was written for a dark one and
   printed the name white on it -- invisible. Ink colours now. */
/* Three lines, one under the other (2026-09-27): side by side in the 220 px rail the name was cut short, the role tag
   sat on the shop list and the Sign out button squeezed both. */
.user-profile-widget {
  padding: var(--sp-3) 4px;
  border-top: 1px solid var(--line);
  display: flex;
  flex-direction: column;
  align-items: stretch;
  gap: 8px;
}

.user-profile-info {
  display: flex;
  flex-direction: column;
  gap: 4px;
  min-width: 0;
}

.user-profile-name {
  font-size: var(--fs-sm);
  font-weight: 600;
  color: var(--ink);
  line-height: 1.3;
  overflow-wrap: anywhere;
}

.user-profile-role {
  font-size: var(--fs-xs);
  color: var(--ink-muted);
  display: flex;
  flex-wrap: wrap;
  align-items: center;
  gap: 4px 6px;
  line-height: 1.4;
}

.user-profile-shops { overflow-wrap: anywhere; }

.user-role-tag {
  display: inline-block;
  padding: 1px 6px;
  border-radius: 4px;
  font-size: var(--fs-xs);
  font-weight: 700;
  color: var(--on-dark);
  white-space: nowrap;
}

.role-superadmin { background: var(--role-superadmin); }
.role-ceo { background: var(--role-ceo); }
.role-cfo { background: var(--role-cfo); }
.role-coo { background: var(--role-coo); }
.role-hr { background: var(--role-hr); }
.role-store_manager { background: var(--role-store-manager); }
.role-floor_advisor { background: var(--role-floor-advisor); }

.btn-auth-logout {
  align-self: flex-start;
  min-height: 32px;
  background: transparent;
  border: 1px solid var(--line-strong);
  color: var(--ink-muted);
  padding: 4px 12px;
  border-radius: 6px;
  font-size: var(--fs-xs);
  cursor: pointer;
  transition: all var(--dur-fast) ease;
}

.btn-auth-logout:hover,
.btn-auth-logout:focus-visible {
  background: var(--danger-wash);
  border-color: var(--danger-vivid);
  color: var(--danger);
}

/* Stage 2 (2026-09-27): the authenticator steps. Tokens only (lint_css.js reads this file). */
.auth-steps { margin: 0 0 var(--sp-4); padding-left: 1.2em; color: var(--ink); font-size: var(--fs-md); line-height: 1.5; }
.auth-steps li { margin-bottom: var(--sp-2); }
.auth-qr { display: flex; justify-content: center; margin: var(--sp-3) 0; }
.auth-qr svg { width: 180px; height: 180px; background: var(--surface); }
.auth-key {
  margin: var(--sp-2) 0;
  padding: var(--sp-2) var(--sp-3);
  border: 1px dashed var(--line-strong);
  border-radius: var(--r-sm);
  background: var(--surface-2);
  font-family: ui-monospace, SFMono-Regular, Menlo, monospace;
  font-size: 15px;
  letter-spacing: 0.08em;
  word-break: break-all;
  user-select: all;
}
.auth-note { color: var(--ink-muted); font-size: var(--fs-sm); margin: var(--sp-1) 0 var(--sp-3); }
.auth-recovery {
  list-style: none;
  margin: 0 0 var(--sp-3);
  padding: var(--sp-3);
  display: grid;
  grid-template-columns: repeat(2, 1fr);
  gap: var(--sp-2);
  border: 1px solid var(--line);
  border-radius: var(--r-sm);
  background: var(--surface-2);
}
.auth-recovery code { font-size: 14px; letter-spacing: 0.05em; }
.auth-row { display: flex; gap: var(--sp-2); margin-bottom: var(--sp-3); flex-wrap: wrap; }
.auth-check { display: flex; align-items: center; gap: var(--sp-2); font-size: var(--fs-md); margin-bottom: var(--sp-2); }
.auth-link {
  background: none;
  border: none;
  padding: 0;
  color: var(--info);
  font: inherit;
  font-weight: 600;
  text-decoration: underline;
  cursor: pointer;
  min-height: 24px;
}
.auth-link:focus-visible { outline: 2px solid var(--info-strong); outline-offset: 2px; }

/* A server run for checks says so before anyone types a real password into it (2026-09-27). */
.auth-testcopy { margin: 0 0 var(--sp-3); padding: 10px 12px; border-radius: var(--r-md); background: var(--warn-soft);
  border: 1px solid var(--warn-line); color: var(--warn); font-size: var(--fs-sm); line-height: 1.45; }
.auth-testcopy[hidden] { display: none; }

/* Trust this browser (2026-09-28): the tick under the code, and the quiet "forget" link under Sign out */
#authForm .auth-check { display: flex; gap: 8px; align-items: flex-start; flex-wrap: wrap; margin: 4px 0 12px; font-size: var(--fs-sm); color: var(--ink); }
#authForm .auth-check .auth-note { flex-basis: 100%; margin: 0 0 0 24px; }
.user-forget { align-self: flex-start; font-size: var(--fs-xs); }
