/* Stand-alone sign-in pages: auth/login.php (office), auth/member-login.php,
   forgot / reset password and email confirmation - framed by
   auth/_auth-open.php and _auth-close.php.

   These sit outside the authenticated shell - no header.php, no app.css - so
   they share this sheet instead. Each portal is one set of variables on
   <body data-portal>: member green, office navy.

   Both portals sit over a full-screen picture, images/login/login-{portal}.webp.
   _auth-open.php sets --auth-photo on the backdrop only when that file exists;
   until then --glow and the portal colour stand in. The office picture is the
   client's own artwork with its baked-in logo painted out (the page draws the
   logo).

   Office: white card, centred, logo above it.
   Member: champagne gold, after the client's mock-up - dark logo top-left,
   a frosted glass card on the right carrying a gold logo and the company
   name, the icon row on glass beneath it. The logos are logo-white.png used
   as a mask, so one file gives both the dark and the gold version. */

:root {
    --auth-ink: #0f172a;
    --auth-ink-soft: #475569;
    --auth-faint: #94a3b8;
    --auth-field: #ffffff;
    --auth-field-border: #dbe2ea;
    --auth-err-bg: #fef2f2;
    --auth-err-ink: #b91c1c;
    --auth-err-border: #fecaca;
    --auth-ok-bg: #f0fdf4;
    --auth-ok-ink: #15803d;
    --auth-ok-border: #bbf7d0;
    --auth-photo: none;
    --field-radius: 12px;
    --submit-ink: #fff;
}

body[data-portal="member"] {
    --accent: #7d5f2c;
    --accent-hover: #664c21;
    --accent-ring: rgba(184, 146, 90, 0.3);
    --accent-soft: rgba(184, 146, 90, 0.12);
    --gold: linear-gradient(135deg, #a57f45 0%, #e3c98f 48%, #b8925a 100%);
    --submit: var(--gold);
    --submit-hover: linear-gradient(135deg, #b08a4f 0%, #ecd6a3 48%, #c6a066 100%);
    --submit-ink: #3b2a12;
    --corner-ink: #2b2118;
    --auth-field: rgba(255, 255, 255, 0.72);
    --auth-autofill: #f8f5ef;
    --field-radius: 999px;
    --glass: rgba(255, 255, 255, 0.45);
    --glass-edge: rgba(255, 255, 255, 0.7);
    /* Stand-in until login-member.webp exists: daylight above, desk below. */
    --glow: linear-gradient(180deg, #ece7df 0%, #d9d0c2 55%, #8a7560 80%, #5a4a3a 100%);
    --backdrop: #5a4a3a;
    --shade: rgba(0, 0, 0, 0);
}

body[data-portal="office"] {
    --accent: #0b2a5b;
    --accent-hover: #12387a;
    --accent-ring: rgba(30, 64, 175, 0.18);
    --accent-soft: rgba(30, 64, 175, 0.08);
    --backdrop: #0b1f45;
    --glow: none;
    --shade: rgba(3, 10, 28, 0.6);
}

* { box-sizing: border-box; margin: 0; padding: 0; }

body {
    font-family: 'Inter', system-ui, sans-serif;
    min-height: 100vh; min-height: 100dvh;
    background: var(--backdrop);
    color: #fff;
    overflow-x: hidden;
    -webkit-font-smoothing: antialiased;
}

/* A fixed layer rather than background-attachment: fixed, which iOS ignores. */
.auth-backdrop {
    position: fixed; inset: 0; z-index: 0; pointer-events: none;
    background:
        linear-gradient(180deg, rgba(0, 0, 0, 0) 55%, var(--shade) 100%),
        var(--auth-photo) center / cover no-repeat,
        var(--glow),
        var(--backdrop);
}


.auth-shell {
    position: relative; z-index: 1;
    min-height: 100vh; min-height: 100dvh;
    display: flex; flex-direction: column; align-items: center; justify-content: center;
    padding: 40px 16px 28px;
}

/* ── Brand ─────────────────────────────────────────────── */
.auth-brand { text-align: center; margin-bottom: 26px; }
.auth-brand img { width: 150px; height: auto; display: block; margin: 0 auto; filter: drop-shadow(0 6px 18px rgba(0, 0, 0, 0.35)); }

/* ── Card ──────────────────────────────────────────────── */
.auth-card {
    width: 100%; max-width: 400px;
    background: rgba(255, 255, 255, 0.95);
    backdrop-filter: blur(18px); -webkit-backdrop-filter: blur(18px);
    border: 1px solid rgba(255, 255, 255, 0.65);
    border-radius: 22px;
    padding: 32px 30px 26px;
    box-shadow: 0 24px 60px rgba(0, 0, 0, 0.35);
    color: var(--auth-ink);
}
.auth-card h1 { font-size: 1.55rem; font-weight: 700; color: var(--accent); text-align: center; letter-spacing: -0.01em; margin-bottom: 22px; }
.auth-card h1::after { content: ""; display: block; width: 36px; height: 3px; border-radius: 2px; background: var(--accent); margin: 10px auto 0; }
.auth-lead { text-align: center; color: var(--auth-ink-soft); font-size: 0.88rem; line-height: 1.5; margin: -8px 0 22px; }

.auth-alert { display: flex; gap: 8px; align-items: flex-start; border-radius: 12px; padding: 10px 14px; font-size: 0.84rem; line-height: 1.45; margin-bottom: 16px; border: 1px solid; }
.auth-alert i { margin-top: 2px; }
.auth-alert-error { background: var(--auth-err-bg); color: var(--auth-err-ink); border-color: var(--auth-err-border); }
.auth-alert-success { background: var(--auth-ok-bg); color: var(--auth-ok-ink); border-color: var(--auth-ok-border); }

/* System switch (office only): a destination, shown up front rather than in a
   dropdown, so the operator sees which system they are entering. */
.auth-switch { display: grid; grid-template-columns: 1fr 1fr; gap: 4px; padding: 4px; background: var(--accent-soft); border-radius: 12px; margin-bottom: 16px; border: 0; }
.auth-switch legend { position: absolute; width: 1px; height: 1px; overflow: hidden; clip: rect(0 0 0 0); }
.auth-switch input { position: absolute; opacity: 0; pointer-events: none; }
.auth-switch label {
    display: flex; align-items: center; justify-content: center; gap: 7px;
    padding: 9px 8px; border-radius: 9px; cursor: pointer;
    font-size: 0.86rem; font-weight: 600; color: var(--auth-ink-soft);
    transition: background 0.2s, color 0.2s, box-shadow 0.2s;
}
.auth-switch input:checked + label { background: #fff; color: var(--accent); box-shadow: 0 1px 4px rgba(15, 23, 42, 0.12); }
.auth-switch input:focus-visible + label { outline: 2px solid var(--accent); outline-offset: 2px; }

.auth-field { position: relative; margin-bottom: 14px; }
.auth-field label { position: absolute; width: 1px; height: 1px; overflow: hidden; clip: rect(0 0 0 0); }
.auth-field > i { position: absolute; left: 16px; top: 50%; transform: translateY(-50%); color: var(--auth-faint); font-size: 0.9rem; pointer-events: none; transition: color 0.2s; }
.auth-field input {
    width: 100%; padding: 13px 46px 13px 44px;
    background: var(--auth-field); border: 1px solid var(--auth-field-border); border-radius: var(--field-radius);
    font: inherit; font-size: 0.93rem; color: var(--auth-ink);
    transition: border-color 0.2s, box-shadow 0.2s; outline: none;
}
.auth-field input::placeholder { color: var(--auth-faint); }
.auth-field input:focus { border-color: var(--accent); box-shadow: 0 0 0 4px var(--accent-ring); }
.auth-field input:focus ~ i { color: var(--accent); }
.auth-field input:-webkit-autofill { -webkit-box-shadow: 0 0 0 40px var(--auth-autofill, var(--auth-field)) inset; -webkit-text-fill-color: var(--auth-ink); }
.auth-pw-toggle {
    position: absolute; right: 8px; top: 50%; transform: translateY(-50%);
    background: none; border: 0; padding: 8px; border-radius: 8px; cursor: pointer;
    color: var(--auth-faint); font-size: 0.9rem; line-height: 1;
}
.auth-pw-toggle:hover { color: var(--auth-ink-soft); }
/* Edge draws its own reveal eye beside ours once the field has content. */
input[type="password"]::-ms-reveal, input[type="password"]::-ms-clear { display: none; }

.auth-submit {
    width: 100%; margin-top: 6px; padding: 13px;
    display: flex; align-items: center; justify-content: center; gap: 10px;
    background: var(--submit, var(--accent)); color: var(--submit-ink); border: 0; border-radius: 999px;
    font: inherit; font-size: 0.95rem; font-weight: 600; cursor: pointer;
    box-shadow: 0 8px 20px var(--accent-ring);
    transition: background 0.2s, transform 0.15s;
}
a.auth-submit { text-decoration: none; }
.auth-submit:hover { background: var(--submit-hover, var(--accent-hover)); }
.auth-submit:active { transform: translateY(1px); }
.auth-submit i { transition: transform 0.2s; }
.auth-submit:hover i { transform: translateX(3px); }

.auth-card-foot { display: flex; justify-content: space-between; align-items: center; gap: 12px; margin-top: 16px; font-size: 0.82rem; color: var(--auth-ink-soft); }
.auth-card-foot:has(> :only-child) { justify-content: center; }
.auth-card-foot a { color: var(--accent); font-weight: 500; text-decoration: underline; text-underline-offset: 3px; }
.auth-card-foot a i { margin-right: 0.4em; }

/* Outcome pages (verify-email): one large icon above the title. */
.auth-result { display: block; text-align: center; font-size: 2.6rem; margin-bottom: 14px; }
.auth-result-ok { color: var(--auth-ok-ink); }
.auth-result-error { color: var(--auth-err-ink); }

.auth-hint { margin-top: 14px; padding-top: 14px; border-top: 1px solid var(--auth-field-border); font-size: 0.78rem; line-height: 1.5; color: var(--auth-ink-soft); text-align: center; }

:focus-visible { outline: 2px solid var(--accent); outline-offset: 2px; }
.auth-sr { position: absolute; width: 1px; height: 1px; overflow: hidden; clip: rect(0 0 0 0); white-space: nowrap; }
.auth-card-foot a:focus-visible, .auth-submit:focus-visible { outline-color: var(--accent); }

/* The footer sits straight on the picture, so the text carries a shadow. */
.auth-foot { text-shadow: 0 1px 3px rgba(0, 0, 0, 0.7), 0 0 12px rgba(0, 0, 0, 0.35); }

.auth-foot { margin-top: 30px; text-align: center; font-size: 0.74rem; color: rgba(255, 255, 255, 0.8); }
.auth-foot a { color: rgba(255, 255, 255, 0.85); text-decoration: none; font-weight: 500; }
.auth-foot a:hover { text-decoration: underline; }
.auth-foot p + p { margin-top: 8px; }

@media (max-width: 640px) {
    /* Still centred: min-height (not height) lets the shell grow past the screen, so a tall page scrolls rather than clipping its top. */
    .auth-shell { padding-top: 32px; }
    .auth-brand { margin-bottom: 20px; }
    .auth-brand img { width: 108px; }
    .auth-shell .auth-card { padding: 26px 20px 22px; border-radius: 18px; }
}

/* ── Member: glass card on the right ───────────────────── */
body[data-portal="member"] .auth-shell { align-items: flex-end; padding: 40px clamp(16px, 9vw, 150px) 28px; }
.auth-column { width: 100%; max-width: 400px; display: flex; flex-direction: column; }

.auth-logo {
    display: block; aspect-ratio: 762 / 469;
    -webkit-mask: url("../../images/login/logo-white.png") center / contain no-repeat;
            mask: url("../../images/login/logo-white.png") center / contain no-repeat;
}
/* The halo keeps the dark logo readable where the photo is dark (the window
   frame runs down that corner). It sits on a wrapper: a filter on the masked
   element itself would be masked away. */
.auth-corner { position: absolute; top: 34px; left: clamp(16px, 7.5vw, 140px); width: 96px; filter: drop-shadow(0 0 1px rgba(255, 255, 255, 0.8)) drop-shadow(0 0 12px rgba(255, 255, 255, 0.6)); }
.auth-corner .auth-logo { background: var(--corner-ink); }

.auth-glass {
    background: var(--glass);
    backdrop-filter: blur(22px) saturate(140%); -webkit-backdrop-filter: blur(22px) saturate(140%);
    border: 1px solid var(--glass-edge);
    box-shadow: 0 24px 60px rgba(40, 28, 12, 0.25), inset 0 1px 0 rgba(255, 255, 255, 0.6);
}
.auth-glass { border-radius: 22px; padding: 30px 30px 24px; color: var(--auth-ink); }

.auth-card-brand { text-align: center; margin-bottom: 24px; }
.auth-card-brand .auth-logo { width: 88px; margin: 0 auto 14px; background: var(--gold); }
.auth-card-brand strong { display: block; font-size: 1.2rem; font-weight: 600; letter-spacing: -0.01em; }
.auth-card-sub { display: block; margin-top: 4px; font-size: 0.8rem; letter-spacing: 0.06em; color: var(--auth-ink-soft); }

/* The glass is the card, so the page's card inside it sheds its own chrome. */
.auth-shell .auth-glass .auth-card { max-width: none; background: none; border: 0; border-radius: 0; box-shadow: none; padding: 0; backdrop-filter: none; -webkit-backdrop-filter: none; }
.auth-glass .auth-card h1 { font-size: 1.15rem; margin-bottom: 18px; }
.auth-glass .auth-card h1::after { background: var(--gold); }

/* The footer sits straight on the picture, so it keeps the shared white-on-shadow. */
body[data-portal="member"] .auth-foot { margin-top: 16px; }

/* A phone has no room beside the photo: centre the card, drop the corner logo. */
@media (max-width: 900px) {
    body[data-portal="member"] .auth-shell { align-items: center; }
    .auth-corner { display: none; }
}
@media (max-width: 640px) {
    .auth-glass { padding: 26px 20px 22px; border-radius: 18px; }
}

@media (prefers-reduced-motion: reduce) {
    *, *::before, *::after { transition: none !important; }
}
