/* ============================================================================
   auth.css — the sign-in threshold, shared by the admin console (index.html)
   and the Staff Portal (member.html).

   Both apps are light working surfaces. The login is the one screen that is not
   a work surface, so it goes deep: the same brand blue at full intensity, so
   entering the app reads as stepping from the field into the light.
   ============================================================================ */

.auth-stage {
    position: fixed;
    inset: 0;
    z-index: 300;
    display: flex;
    align-items: center;
    justify-content: center;
    padding: 24px;
    overflow: hidden;
    isolation: isolate;

    /* Deep navy ground, lit from upper-left. Built from the same blue family as
       primary #005bbf rather than a neutral dark. */
    background:
        radial-gradient(120% 90% at 15% 0%, #0a3f8a 0%, rgba(10, 63, 138, 0) 55%),
        radial-gradient(100% 80% at 100% 100%, #00306b 0%, rgba(0, 48, 107, 0) 60%),
        linear-gradient(160deg, #062a5e 0%, #041634 55%, #030f26 100%);
}

/* --- Aurora: three slow drifting light fields --------------------------- */

.auth-stage__aurora {
    position: absolute;
    inset: -20%;
    pointer-events: none;
    z-index: -2;
}

.auth-stage__aurora span {
    position: absolute;
    display: block;
    border-radius: 9999px;
    filter: blur(90px);
    opacity: 0.6;
    will-change: transform;
}

.auth-stage__aurora span:nth-child(1) {
    width: 46vw;
    height: 46vw;
    min-width: 320px;
    min-height: 320px;
    top: 4%;
    left: 6%;
    background: #0a6cd8;
    animation: authDrift1 34s ease-in-out infinite alternate;
}

.auth-stage__aurora span:nth-child(2) {
    width: 38vw;
    height: 38vw;
    min-width: 260px;
    min-height: 260px;
    bottom: 2%;
    right: 8%;
    background: #0ea5e9;
    opacity: 0.4;
    animation: authDrift2 42s ease-in-out infinite alternate;
}

.auth-stage__aurora span:nth-child(3) {
    width: 30vw;
    height: 30vw;
    min-width: 220px;
    min-height: 220px;
    top: 42%;
    left: 52%;
    background: #1e3a8a;
    opacity: 0.5;
    animation: authDrift3 38s ease-in-out infinite alternate;
}

@keyframes authDrift1 {
    from { transform: translate3d(0, 0, 0) scale(1); }
    to   { transform: translate3d(6vw, 5vh, 0) scale(1.12); }
}
@keyframes authDrift2 {
    from { transform: translate3d(0, 0, 0) scale(1.08); }
    to   { transform: translate3d(-7vw, -4vh, 0) scale(1); }
}
@keyframes authDrift3 {
    from { transform: translate3d(0, 0, 0) scale(1); }
    to   { transform: translate3d(-4vw, 6vh, 0) scale(1.16); }
}

/* --- Texture: signal lines + grain + vignette ---------------------------- */
/* The fine diagonal rule is a nod to broadcast scan lines — this product is a
   broadcast equipment room. It stays under 4% opacity so it reads as material,
   not as a pattern competing with the card. */

.auth-stage__texture {
    position: absolute;
    inset: 0;
    pointer-events: none;
    z-index: -1;
    background-image:
        repeating-linear-gradient(
            105deg,
            rgba(255, 255, 255, 0.035) 0px,
            rgba(255, 255, 255, 0.035) 1px,
            transparent 1px,
            transparent 7px
        ),
        radial-gradient(120% 90% at 50% 40%, rgba(0, 0, 0, 0) 45%, rgba(2, 8, 22, 0.6) 100%);
}

/* Fine grain keeps the large gradient fields from banding on wide displays. */
.auth-stage__texture::after {
    content: "";
    position: absolute;
    inset: 0;
    opacity: 0.055;
    mix-blend-mode: overlay;
    background-image: url("data:image/svg+xml,%3Csvg xmlns='http://www.w3.org/2000/svg' width='160' height='160'%3E%3Cfilter id='n'%3E%3CfeTurbulence type='fractalNoise' baseFrequency='0.9' numOctaves='3'/%3E%3C/filter%3E%3Crect width='160' height='160' filter='url(%23n)'/%3E%3C/svg%3E");
}

/* --- The card ------------------------------------------------------------
   "Monolith": a near-black slab that sits into the dark field rather than on
   top of it. One ghost button, one status dot, everything on a single centre
   axis. Nothing decorative — it reads as part of the application, not as a
   dialog dropped over it.
   -------------------------------------------------------------------------- */

.auth-card {
    position: relative;
    z-index: 1;
    width: 100%;
    max-width: 372px;
    padding: 38px 32px 30px;
    border-radius: 20px;
    text-align: center;

    background: linear-gradient(180deg, rgba(20, 32, 52, 0.90) 0%, rgba(11, 20, 36, 0.94) 100%);
    border: 1px solid rgba(255, 255, 255, 0.10);
    backdrop-filter: blur(22px) saturate(130%);
    -webkit-backdrop-filter: blur(22px) saturate(130%);
    box-shadow:
        inset 0 1px 0 rgba(255, 255, 255, 0.09),
        0 2px 10px rgba(0, 0, 0, 0.30),
        0 30px 70px -26px rgba(0, 0, 0, 0.85);
    animation: authCardIn 0.55s cubic-bezier(0.16, 1, 0.3, 1) both;
}

@keyframes authCardIn {
    from { opacity: 0; transform: translateY(14px) scale(0.985); }
    to   { opacity: 1; transform: none; }
}

/* --- Lockup --------------------------------------------------------------
   The wordmark asset only reads NOMOREWORK, so the product half of the name
   is set beside it and divided by a hairline — master brand, then product,
   the way a sub-brand is normally locked up. This is the name, not a tagline.
   -------------------------------------------------------------------------- */

.auth-lockup {
    display: flex;
    align-items: center;
    justify-content: center;
    gap: 13px;
    margin-bottom: 36px;
}

.auth-card__logo {
    height: 40px;
    object-fit: contain;
    display: block;
    filter: brightness(0) invert(1);
    opacity: 0.95;
    flex-shrink: 0;
}

.auth-lockup__rule {
    width: 1px;
    height: 26px;
    flex-shrink: 0;
    background: linear-gradient(180deg,
        rgba(255, 255, 255, 0) 0%,
        rgba(255, 255, 255, 0.28) 50%,
        rgba(255, 255, 255, 0) 100%);
}

.auth-lockup__product {
    font-size: 12px;
    font-weight: 600;
    letter-spacing: 0.17em;
    text-transform: uppercase;
    color: #93aecf;
    white-space: nowrap;
    /* optical: tracking adds trailing space, pull it back so the lockup
       reads as one unit rather than a word floating off the rule */
    margin-right: -0.17em;
}

/* --- The single action --------------------------------------------------- */

/* Ghost, not solid. On a slab this dark a white block would punch a hole in
   the surface; an outlined face keeps the card reading as one piece. */
.auth-btn-google {
    width: 100%;
    min-height: 50px;
    display: flex;
    align-items: center;
    justify-content: center;
    gap: 10px;
    padding: 0 18px;
    border-radius: 12px;
    border: 1px solid rgba(255, 255, 255, 0.18);
    background: rgba(255, 255, 255, 0.075);
    font-family: inherit;
    font-size: 13.5px;
    font-weight: 600;
    color: #ffffff;
    cursor: pointer;
    transition: background 0.2s ease, border-color 0.2s ease, transform 0.2s cubic-bezier(0.16, 1, 0.3, 1);
}

.auth-btn-google:hover {
    background: rgba(255, 255, 255, 0.13);
    border-color: rgba(255, 255, 255, 0.30);
}

.auth-btn-google:active {
    transform: scale(0.985);
}

.auth-btn-google svg {
    width: 18px;
    height: 18px;
    flex-shrink: 0;
}

/* Secondary actions inside the non-default states. */
.auth-btn-quiet {
    width: 100%;
    min-height: 46px;
    border-radius: 12px;
    border: 1px solid rgba(255, 255, 255, 0.14);
    background: rgba(255, 255, 255, 0.05);
    color: #dce7f6;
    font-family: inherit;
    font-size: 13px;
    font-weight: 600;
    cursor: pointer;
    transition: background 0.2s ease, border-color 0.2s ease;
}
.auth-btn-quiet:hover {
    background: rgba(255, 255, 255, 0.11);
    border-color: rgba(255, 255, 255, 0.24);
}

/* --- Status line --------------------------------------------------------- */

/* The dot is drawn from CSS so the markup stays just logo + button + line.
   Static, not pulsing — the drifting field is this screen's only motion. */
.auth-note {
    margin-top: 18px;
    display: flex;
    align-items: center;
    justify-content: center;
    gap: 7px;
    font-size: 11px;
    font-weight: 500;
    color: #7f97b8;
}
.auth-note::before {
    content: "";
    width: 5px;
    height: 5px;
    border-radius: 9999px;
    background: #34d399;
    flex-shrink: 0;
}
.auth-note strong {
    color: #a9c4e6;
    font-weight: 600;
}

/* --- Non-default states -------------------------------------------------- */

.auth-msg {
    font-size: 13px;
    font-weight: 600;
    color: #e6eefb;
    line-height: 1.5;
}
.auth-sub {
    margin-top: 5px;
    font-size: 11.5px;
    font-weight: 500;
    color: #8ba4c4;
    line-height: 1.55;
}
.auth-email {
    display: block;
    margin-bottom: 4px;
    font-weight: 700;
    color: #ffffff;
    word-break: break-all;
}

@media (max-width: 420px) {
    .auth-card { padding: 32px 24px 26px; border-radius: 18px; }
    .auth-lockup { gap: 11px; margin-bottom: 32px; }
    .auth-card__logo { height: 34px; }
    .auth-lockup__rule { height: 22px; }
    .auth-lockup__product { font-size: 11px; letter-spacing: 0.15em; }
}

/* The lockup is a fixed-width row of three parts, so it is the first thing to
   run out of room. On a 320px phone the full-size version overflows the card
   by 12px — step it down rather than letting it clip. */
@media (max-width: 360px) {
    .auth-lockup { gap: 9px; }
    .auth-card__logo { height: 30px; }
    .auth-lockup__rule { height: 19px; }
    .auth-lockup__product { font-size: 10px; letter-spacing: 0.12em; }
}

/* --- Reduced motion ----------------------------------------------------- */
/* The drift is atmosphere, not information. Hold it still on request. */

@media (prefers-reduced-motion: reduce) {
    .auth-stage__aurora span,
    .auth-card {
        animation: none !important;
    }
}

/* --- State blocks (layout only) -------------------------------------------
   The Staff Portal redesign ships hand-written CSS and does NOT load Tailwind,
   so the utility classes these blocks used (flex-col / items-center / gap-3 /
   w-full) silently did nothing there. These rules reproduce that layout in
   plain CSS so the card lays out identically on every page.
   Layout only — no colour, size or spacing of the login was changed.
   -------------------------------------------------------------------------- */

.auth-state {
    display: flex;
    flex-direction: column;
    align-items: center;
    gap: 12px;
    width: 100%;
}

.auth-state.hidden {
    display: none !important;
}

.auth-spin {
    display: inline-block;
    animation: authSpin 0.9s linear infinite;
}

@keyframes authSpin {
    to { transform: rotate(360deg); }
}

@media (prefers-reduced-motion: reduce) {
    .auth-spin { animation-duration: 2.4s; }
}

/* --- Credential form ------------------------------------------------------
   Username + password is now the primary way in, with Google kept as an
   alternative. Written in plain CSS with no utility classes: member.html does
   not load Tailwind, so anything shared has to stand on its own.
   -------------------------------------------------------------------------- */

.auth-pane { display: none; }
.auth-pane.is-active { display: block; }

.auth-field { margin-bottom: 12px; text-align: left; }

.auth-label {
    display: block;
    font-size: 11px;
    font-weight: 600;
    color: #93aecf;
    margin-bottom: 5px;
}

/* Qualified as `input.auth-input`, not just `.auth-input`. index.html loads
   Tailwind with the `forms` plugin, which resets every [type="password"] (and
   text/email/etc.) input to a white, square-cornered field via an attribute
   selector — same specificity (0,1,0) as a bare class selector. At equal
   specificity the one injected later in the document wins, and Tailwind's
   CDN <script> injects its stylesheet after this file's <link>, so the plain
   class alone silently lost on every field except the username input (which
   is shielded by the extra `.auth-suffix` ancestor class). Adding the `input`
   element to the selector raises specificity to (0,1,1), which beats the
   attribute selector regardless of load order or which page loads Tailwind. */
input.auth-input {
    width: 100%;
    min-height: 44px;
    padding: 0 13px;
    border-radius: 11px;
    border: 1px solid rgba(255, 255, 255, 0.16);
    background: rgba(255, 255, 255, 0.06);
    color: #ffffff;
    font-family: inherit;
    font-size: 14px;
    font-weight: 500;
    outline: none;
    transition: border-color 0.2s ease, background 0.2s ease, box-shadow 0.2s ease;
}
input.auth-input::placeholder { color: #6f88a8; font-weight: 400; }
input.auth-input:focus {
    border-color: rgba(120, 170, 240, 0.65);
    background: rgba(255, 255, 255, 0.10);
    box-shadow: 0 0 0 3px rgba(90, 150, 230, 0.18);
}
input.auth-input:disabled { opacity: 0.55; cursor: not-allowed; }

/* The username field shows the domain it will become, so nobody wonders
   whether to type the whole address. */
.auth-suffix {
    display: flex;
    align-items: center;
    border-radius: 11px;
    border: 1px solid rgba(255, 255, 255, 0.16);
    background: rgba(255, 255, 255, 0.06);
    transition: border-color 0.2s ease, background 0.2s ease, box-shadow 0.2s ease;
}
.auth-suffix:focus-within {
    border-color: rgba(120, 170, 240, 0.65);
    background: rgba(255, 255, 255, 0.10);
    box-shadow: 0 0 0 3px rgba(90, 150, 230, 0.18);
}
.auth-suffix .auth-input {
    border: none;
    background: transparent;
    box-shadow: none;
    flex: 1;
    min-width: 0;
}
.auth-suffix .auth-input:focus { box-shadow: none; background: transparent; }
.auth-suffix__tail {
    padding: 0 13px 0 4px;
    font-size: 12.5px;
    font-weight: 600;
    color: #7f97b8;
    white-space: nowrap;
    flex-shrink: 0;
}

.auth-btn-primary {
    width: 100%;
    min-height: 48px;
    margin-top: 4px;
    border-radius: 12px;
    border: none;
    background: #2f6ef5;
    color: #ffffff;
    font-family: inherit;
    font-size: 14px;
    font-weight: 700;
    cursor: pointer;
    transition: filter 0.2s ease, transform 0.2s cubic-bezier(0.16, 1, 0.3, 1);
}
.auth-btn-primary:hover { filter: brightness(1.1); }
.auth-btn-primary:active { transform: scale(0.985); }
.auth-btn-primary:disabled { opacity: 0.55; cursor: not-allowed; filter: none; }

.auth-links {
    display: flex;
    align-items: center;
    justify-content: space-between;
    gap: 10px;
    margin-top: 12px;
}
.auth-link {
    background: none;
    border: none;
    padding: 0;
    font-family: inherit;
    font-size: 11.5px;
    font-weight: 600;
    color: #93aecf;
    cursor: pointer;
    transition: color 0.2s ease;
}
.auth-link:hover { color: #ffffff; text-decoration: underline; }

/* Google drops below a rule — still available, no longer the headline. */
.auth-divider {
    display: flex;
    align-items: center;
    gap: 10px;
    margin: 18px 0 14px;
    font-size: 10.5px;
    font-weight: 600;
    color: #6f88a8;
}
.auth-divider::before,
.auth-divider::after {
    content: "";
    flex: 1;
    height: 1px;
    background: rgba(255, 255, 255, 0.12);
}

.auth-feedback {
    margin-top: 12px;
    font-size: 11.5px;
    font-weight: 600;
    line-height: 1.55;
    text-align: left;
}
.auth-feedback.is-error { color: #ff9b9b; }
.auth-feedback.is-ok    { color: #6ee7b7; }

/* Browser autofill repaints inputs with its own near-white background, which on
   a dark card leaves one field glowing white next to the others. There is no way
   to unset it, so the inset shadow is used to paint over it instead. */
.auth-input:-webkit-autofill,
.auth-input:-webkit-autofill:hover,
.auth-input:-webkit-autofill:focus,
.auth-input:-webkit-autofill:active {
    -webkit-text-fill-color: #ffffff;
    -webkit-box-shadow: 0 0 0 1000px #1b2740 inset;
            box-shadow: 0 0 0 1000px #1b2740 inset;
    caret-color: #ffffff;
    /* the colour is applied on a delay long enough never to be reached */
    transition: background-color 9999s ease-out 9999s;
}
