/* SafeSurf webkit design system — shared by BOTH consoles.
 *
 * Provenance: extracted on 2026-10-06 from the operator console's
 * internal/adminportal/web/app.css (adapted from N4L/internal/cp/portal/app.css
 * and re-branded to SafeSurf). COPIED, never imported. The operator-only
 * break-glass banner (.bg-banner) stays in the operator console's own app.css.
 * Palette derived from the apps' SafeSurf theme (iOS Theme.swift / android
 * Color.kt): primary #007AFF, teal #00C9A7, success #34C759, warning #FF9500,
 * danger #FF3B30, deep-navy dark surfaces #1A1A2E/#16213E.
 * Colours are tokens on :root, redefined for dark mode. WCAG AA contrast.
 * No @import, no remote assets — everything is self-hosted (strict CSP). */
:root {
  --bg: #eef2f8;
  --surface: #ffffff;
  --surface-2: #f3f6fb;
  --surface-3: #e7edf6;
  --border: #d4deec;
  --border-strong: #b9c7de;
  --text: #10203b;
  --text-muted: #566783;
  --text-faint: #556785;     /* AA (>=4.5) on --bg and --surface for small text */

  --primary: #0062cc;        /* AA with white text */
  --primary-strong: #004fa3;
  --primary-soft: #e4effb;
  --accent: #008e78;         /* teal, AA on white */
  --ok: #147d2d;             /* AA (4.67) as chip/pill/tag text on --ok-soft */
  --ok-soft: #e4f6ea;
  --warn: #9a6200;           /* amber text, AA on white */
  --warn-soft: #fdf0dc;
  --danger: #b02a21;         /* AA (5.48) as text on --danger-soft, 6.56 on white */
  --danger-soft: #fbe6e4;

  --ring: rgba(0, 122, 255, 0.35);
  --shadow: 0 1px 2px rgba(16, 32, 59, 0.06), 0 6px 20px rgba(16, 32, 59, 0.06);
  --shadow-lg: 0 10px 40px rgba(16, 32, 59, 0.14);
  --radius: 12px;
  --radius-sm: 8px;
  --gap: 16px;
  --sidebar-w: 248px;
  --font: -apple-system, BlinkMacSystemFont, "Segoe UI", Roboto, Helvetica, Arial, sans-serif;
  --mono: ui-monospace, SFMono-Regular, Menlo, Consolas, monospace;
}

/* Dark theme: applied when data-theme="dark", and as the OS default unless the
 * user forced light (data-theme="light"). Both selectors keep specificity simple. */
@media (prefers-color-scheme: dark) {
  :root:not([data-theme="light"]) {
    --bg: #0e1626;
    --surface: #16213e;
    --surface-2: #1b294a;
    --surface-3: #22335a;
    --border: #2c3d60;
    --border-strong: #3a4f78;
    --text: #e9f0fb;
    --text-muted: #a9bada;
    --text-faint: #8296b8;

    --primary: #4da3ff;
    --primary-strong: #7cbcff;
    --primary-soft: #16294a;
    --accent: #2fd4b4;
    --ok: #46d06a;
    --ok-soft: #123524;
    --warn: #ffb547;
    --warn-soft: #3a2a10;
    --danger: #ff6f63;
    --danger-soft: #3a1b1a;

    --ring: rgba(77, 163, 255, 0.4);
    --shadow: 0 1px 2px rgba(0, 0, 0, 0.3), 0 8px 24px rgba(0, 0, 0, 0.3);
    --shadow-lg: 0 12px 44px rgba(0, 0, 0, 0.5);
  }
}
:root[data-theme="dark"] {
  --bg: #0e1626;
  --surface: #16213e;
  --surface-2: #1b294a;
  --surface-3: #22335a;
  --border: #2c3d60;
  --border-strong: #3a4f78;
  --text: #e9f0fb;
  --text-muted: #a9bada;
  --text-faint: #8296b8;

  --primary: #4da3ff;
  --primary-strong: #7cbcff;
  --primary-soft: #16294a;
  --accent: #2fd4b4;
  --ok: #46d06a;
  --ok-soft: #123524;
  --warn: #ffb547;
  --warn-soft: #3a2a10;
  --danger: #ff6f63;
  --danger-soft: #3a1b1a;

  --ring: rgba(77, 163, 255, 0.4);
  --shadow: 0 1px 2px rgba(0, 0, 0, 0.3), 0 8px 24px rgba(0, 0, 0, 0.3);
  --shadow-lg: 0 12px 44px rgba(0, 0, 0, 0.5);
}

* { box-sizing: border-box; }
html, body { height: 100%; }
body {
  margin: 0;
  font-family: var(--font);
  background: var(--bg);
  color: var(--text);
  font-size: 15px;
  line-height: 1.5;
  -webkit-font-smoothing: antialiased;
}
a { color: var(--primary); text-decoration: none; }
a:hover { text-decoration: underline; }
h1 { font-size: 1.6rem; margin: 0 0 14px; letter-spacing: -0.01em; }
h2 { font-size: 1.1rem; margin: 0 0 12px; }
h3 { font-size: 1rem; margin: 0 0 8px; }
code { font-family: var(--mono); background: var(--surface-2); padding: 1px 5px; border-radius: 5px; font-size: 0.86em; }
.muted { color: var(--text-muted); }

.splash, .loading {
  display: flex; align-items: center; justify-content: center; gap: 10px;
  min-height: 60vh; color: var(--text-muted);
}
.spinner {
  width: 18px; height: 18px; border-radius: 50%;
  border: 2px solid var(--border-strong); border-top-color: var(--primary);
  animation: spin 0.7s linear infinite; display: inline-block;
}
@keyframes spin { to { transform: rotate(360deg); } }

/* ---- focus + accessibility ---- */
:focus-visible { outline: 3px solid var(--ring); outline-offset: 2px; border-radius: 4px; }
.skip {
  position: absolute; left: -999px; top: 8px; z-index: 100;
  background: var(--surface); color: var(--text); padding: 8px 14px; border-radius: 8px; box-shadow: var(--shadow);
}
.skip:focus { left: 8px; }

/* ---- layout ---- */
.layout { display: grid; grid-template-columns: var(--sidebar-w) 1fr; min-height: 100vh; }
.side {
  background: var(--surface); border-right: 1px solid var(--border);
  display: flex; flex-direction: column; gap: 2px; padding: 16px 12px;
  position: sticky; top: 0; height: 100vh; overflow-y: auto;
}
.brand { display: flex; align-items: center; gap: 10px; padding: 4px 8px 10px; }
.brand-mark img { display: block; width: 34px; height: 34px; border-radius: 9px; }
.brand-text { line-height: 1.1; }
.brand-name { font-weight: 800; letter-spacing: -0.02em; font-size: 1.15rem; }
.brand-name b { color: var(--primary); font-weight: 800; }
.brand-sub { font-size: 0.72rem; color: var(--text-muted); letter-spacing: 0.04em; text-transform: uppercase; }
.nav-group-label {
  font-size: 0.68rem; text-transform: uppercase; letter-spacing: 0.08em;
  color: var(--text-faint); padding: 14px 10px 4px;
}
.navlink {
  display: flex; align-items: center; gap: 10px; padding: 9px 11px; border-radius: 10px;
  color: var(--text); font-weight: 500; font-size: 0.93rem;
}
.navlink:hover { background: var(--surface-2); text-decoration: none; }
.navlink.on { background: var(--primary-soft); color: var(--primary-strong); font-weight: 650; }
.navlink.on .nav-ico { color: var(--primary); }
.nav-ico { width: 20px; height: 20px; color: var(--text-muted); flex: none; }
.ico { width: 18px; height: 18px; flex: none; vertical-align: -3px; }
.ico-sm { width: 14px; height: 14px; }
.nav-spacer { flex: 1 1 auto; }
.who {
  display: flex; align-items: center; gap: 10px; padding: 10px 8px 2px;
  border-top: 1px solid var(--border); margin-top: 8px;
}
.avatar {
  width: 34px; height: 34px; border-radius: 50%; flex: none;
  background: var(--primary); color: #fff; display: flex; align-items: center; justify-content: center;
  font-weight: 700; font-size: 0.8rem;
}
.who-text { min-width: 0; flex: 1; }
.who-name { font-weight: 600; font-size: 0.88rem; overflow: hidden; text-overflow: ellipsis; white-space: nowrap; }
.who-role { font-size: 0.74rem; color: var(--text-muted); }
.signout { color: var(--text-muted); padding: 6px; border-radius: 8px; }
.signout:hover { background: var(--surface-2); color: var(--danger); }

.main-col { display: flex; flex-direction: column; min-width: 0; }
.topbar {
  display: flex; align-items: center; gap: 12px; padding: 12px 24px;
  border-bottom: 1px solid var(--border); background: var(--surface); position: sticky; top: 0; z-index: 20;
}
.topbar-spacer { flex: 1; }
.crumbs { display: flex; align-items: center; gap: 8px; font-size: 0.9rem; min-width: 0; }
.c-root { font-weight: 700; color: var(--primary); }
.c-sep { color: var(--text-faint); }
.c-here { color: var(--text-muted); }
.c-id { color: var(--text); font-family: var(--mono); font-size: 0.82rem; overflow: hidden; text-overflow: ellipsis; white-space: nowrap; max-width: 28ch; }
.tb-date { display: inline-flex; align-items: center; gap: 6px; color: var(--text-muted); font-size: 0.85rem; }
.nav-toggle { display: none; }
.nav-backdrop { display: none; }
main { padding: 24px; max-width: 1200px; width: 100%; }

/* ---- buttons + inputs ---- */
button, .btn {
  font: inherit; cursor: pointer; border: 1px solid var(--border-strong);
  background: var(--surface); color: var(--text); padding: 8px 14px; border-radius: var(--radius-sm);
  font-weight: 600; transition: background 0.12s, border-color 0.12s;
}
button:hover, .btn:hover { background: var(--surface-2); }
button:disabled { opacity: 0.5; cursor: not-allowed; }
button.primary, .btn.primary { background: var(--primary); border-color: var(--primary); color: #fff; }
button.primary:hover { background: var(--primary-strong); border-color: var(--primary-strong); }
/* Dark theme only: the dark --primary (#4da3ff) is light, so white text on it fails
 * WCAG AA (~2.63:1). Use dark ink instead (matches the apps' dark primary button).
 * Light theme is unchanged — white text stays AA on the darker light --primary. */
@media (prefers-color-scheme: dark) {
  :root:not([data-theme="light"]) button.primary,
  :root:not([data-theme="light"]) .btn.primary { color: #0e1626; }
}
:root[data-theme="dark"] button.primary,
:root[data-theme="dark"] .btn.primary { color: #0e1626; }
button.danger, .btn.danger { color: var(--danger); border-color: var(--danger); background: var(--surface); }
button.danger:hover { background: var(--danger-soft); }
.link-btn { background: none; border: none; color: var(--primary); padding: 0; font-weight: 600; }
.link-btn:hover { text-decoration: underline; background: none; }

input, select, textarea {
  font: inherit; color: var(--text); background: var(--surface); width: 100%;
  border: 1px solid var(--border-strong); border-radius: var(--radius-sm); padding: 8px 10px;
}
input:focus, select:focus, textarea:focus { border-color: var(--primary); outline: none; box-shadow: 0 0 0 3px var(--ring); }
label { display: block; font-weight: 600; font-size: 0.85rem; margin-bottom: 5px; }
.hint { font-size: 0.8rem; color: var(--text-muted); margin-top: 5px; }
.field { margin-bottom: 14px; }

/* Checkboxes / radios are natural-sized (NOT full-width — the generic input rule
 * above would otherwise stretch them and float the glyph), branded, and laid out
 * inline next to their label via field()'s .field-check layout. This also fixes raw
 * checkboxes in rowEditor cells. */
input[type="checkbox"], input[type="radio"] { width: auto; margin: 0; flex: none; accent-color: var(--primary); }
.field-check { margin-bottom: 14px; }
.field-check .check-label {
  display: inline-flex; align-items: center; gap: 8px; margin-bottom: 0; cursor: pointer;
}
.field-check .check-text { font-weight: 600; font-size: 0.85rem; }
.field-check .hint { margin-top: 6px; }
.row { display: flex; gap: 14px; flex-wrap: wrap; align-items: flex-end; }
.row > * { flex: 1 1 180px; }

/* Disabled form controls (stage 11b lock UI + general): clearly greyed but still
 * legible. --text on --surface-2 keeps AA contrast in light and dark. */
input:disabled, select:disabled, textarea:disabled {
  opacity: 0.6; cursor: not-allowed; background: var(--surface-2); color: var(--text);
}

/* Co-parent permission lock (stage 11b, SS.lockControls). The frozen caption
 * "Ask <primary> to change this" shown beside every locked control group; a
 * restricted co-parent sees the editing controls present but disabled. --text on
 * --surface-2 is AA in both themes; the glyph uses the amber warn tone. */
.lock-note {
  display: flex; align-items: center; gap: 8px;
  margin: 0 0 12px; padding: 8px 12px;
  background: var(--surface-2); border: 1px solid var(--border-strong);
  border-left: 3px solid var(--warn);
  border-radius: var(--radius-sm);
  color: var(--text); font-size: 0.82rem; font-weight: 600;
}
.lock-note .ico-sm { color: var(--warn); flex: none; }
.lock-note-t { color: var(--text); }
.is-locked { position: relative; }

/* ---- cards + panels ---- */
.cards { display: grid; grid-template-columns: repeat(auto-fill, minmax(190px, 1fr)); gap: var(--gap); margin-bottom: var(--gap); }
.card, .panel {
  background: var(--surface); border: 1px solid var(--border); border-radius: var(--radius);
  padding: 18px; box-shadow: var(--shadow);
}
.panel { margin-bottom: var(--gap); }
.stat .stat-top { display: flex; align-items: center; gap: 12px; }
.stat-ico { width: 40px; height: 40px; border-radius: 11px; display: flex; align-items: center; justify-content: center; flex: none; background: var(--primary-soft); color: var(--primary); }
.stat-ico.t-ok { background: var(--ok-soft); color: var(--ok); }
.stat-ico.t-warn { background: var(--warn-soft); color: var(--warn); }
.stat-ico.t-bad { background: var(--danger-soft); color: var(--danger); }
.stat-ico.t-accent { background: color-mix(in srgb, var(--accent) 16%, transparent); color: var(--accent); }
.stat-main { min-width: 0; }
.stat .v { font-size: 1.5rem; font-weight: 750; letter-spacing: -0.02em; }
.stat .v.v-id { font-size: 1rem; font-family: var(--mono); }
.stat .k { font-size: 0.82rem; color: var(--text-muted); }
.stat-sub { margin-top: 8px; font-size: 0.8rem; }

/* ---- tables ---- */
table { width: 100%; border-collapse: collapse; font-size: 0.9rem; }
thead th {
  text-align: left; font-size: 0.74rem; text-transform: uppercase; letter-spacing: 0.05em;
  color: var(--text-muted); padding: 8px 10px; border-bottom: 1px solid var(--border); position: sticky; top: 0; background: var(--surface);
}
tbody td { padding: 9px 10px; border-bottom: 1px solid var(--border); vertical-align: middle; }
tbody tr:last-child td { border-bottom: none; }
tbody tr:hover { background: var(--surface-2); }
.tbl-scroll { max-height: 420px; overflow-y: auto; }
/* Horizontal scroller for a table that can outgrow a narrow panel (e.g. the parent
 * Recent-activity table with a nowrap outcome chip at phone width): the table
 * scrolls sideways INSIDE its panel instead of forcing the whole page to scroll. */
.tbl-scroll-x { overflow-x: auto; -webkit-overflow-scrolling: touch; }
.empty-state { padding: 28px 10px; text-align: center; }
.empty-action { font-weight: 600; }

/* ---- chips, pills, badges ---- */
/* A chip/pill is a single-line label: white-space:nowrap keeps the full 999px
 * radius reading as a pill, never an oval, when the longest labels (the stage-12
 * "Security threat · Phishing/Malware" outcome and "Paused by schedule") land in a
 * cramped cell at phone width. Tables that can outgrow their panel because of a
 * nowrap chip scroll horizontally inside it (.tbl-scroll-x), not the whole page. */
.chip, .pill {
  display: inline-flex; align-items: center; gap: 5px; font-size: 0.76rem; font-weight: 650;
  padding: 2px 9px; border-radius: 999px; background: var(--surface-3); color: var(--text-muted);
  white-space: nowrap;
}
.pill.up, .chip.ok { background: var(--ok-soft); color: var(--ok); }
.pill.down, .chip.bad, .chip.blocked { background: var(--danger-soft); color: var(--danger); }
.pill.degraded, .chip.warn { background: var(--warn-soft); color: var(--warn); }
.chip.allowed { background: var(--ok-soft); color: var(--ok); }
.chip.plain { background: var(--surface-3); color: var(--text); }
.badge-admin { background: var(--primary-soft); color: var(--primary-strong); }
.badge-support { background: var(--surface-3); color: var(--text-muted); }

/* ---- messages / banners ---- */
.msg { padding: 10px 14px; border-radius: var(--radius-sm); font-size: 0.9rem; margin-bottom: 12px; border: 1px solid transparent; }
.msg.ok { background: var(--ok-soft); color: var(--ok); border-color: color-mix(in srgb, var(--ok) 35%, transparent); }
.msg.err { background: var(--danger-soft); color: var(--danger); border-color: color-mix(in srgb, var(--danger) 35%, transparent); }
.msg.warn { background: var(--warn-soft); color: var(--warn); border-color: color-mix(in srgb, var(--warn) 35%, transparent); }
.msg.info { background: var(--primary-soft); color: var(--primary-strong); border-color: color-mix(in srgb, var(--primary) 30%, transparent); }
.msg.banner { font-weight: 600; }

/* ---- legend (helpLegend) ---- */
details.legend { padding: 0; }
details.legend summary { cursor: pointer; padding: 14px 18px; font-weight: 600; }
details.legend[open] summary { border-bottom: 1px solid var(--border); }
.legend-body { padding: 14px 18px; }
.legend-intro, .legend-foot { margin: 0 0 10px; }
.legend-dl { display: grid; grid-template-columns: auto 1fr; gap: 6px 16px; margin: 0; }
.legend-dl dt { font-weight: 600; }
.legend-dl dd { margin: 0; }
.leg-term-tag { display: inline-block; background: var(--surface-3); color: var(--text-muted); border-radius: 6px; padding: 1px 7px; font-size: 0.8rem; }

/* ---- chip-list ---- */
.chip-list-chips { display: flex; flex-wrap: wrap; gap: 6px; margin-bottom: 8px; }
.chip-rm { background: var(--surface-3); color: var(--text); }
.chip-x { background: none; border: none; padding: 0; margin: 0; color: var(--text-muted); display: inline-flex; cursor: pointer; }
.chip-x:hover { color: var(--danger); background: none; }
.chip-list-none { font-size: 0.85rem; }
.chip-list-add-row { display: flex; gap: 8px; align-items: center; }
.chip-list-input { flex: 1; }
.chip-list-err { margin-top: 6px; }

/* ---- row editor ---- */
.row-editor-scroll { overflow-x: auto; }
.row-editor table { font-size: 0.88rem; }
.row-editor tr.is-bad td { background: var(--danger-soft); }
.row-editor-warn { padding-top: 0; }
.row-editor-warn-t { color: var(--danger); font-size: 0.8rem; }
.row-editor-actions { margin-top: 10px; }
.row-editor-paste-d { margin-top: 10px; }

/* ---- inline form ---- */
.inline-form { max-width: 460px; }
.inline-form-title { margin-top: 0; }
.inline-form-actions { margin-top: 10px; }

/* ---- pager ---- */
.pager { display: flex; align-items: center; gap: 10px; justify-content: flex-end; margin-top: 12px; font-size: 0.88rem; color: var(--text-muted); }
.pager button { padding: 5px 11px; }

/* ---- theme toggle ---- */
.theme-toggle { padding: 7px; border-radius: 9px; line-height: 0; color: var(--text-muted); }
.theme-toggle:hover { color: var(--primary); }

/* ---- toast ---- */
.toast-wrap { position: fixed; bottom: 20px; right: 20px; display: flex; flex-direction: column; gap: 8px; z-index: 200; }
.toast { background: var(--surface); border: 1px solid var(--border); border-radius: var(--radius-sm); box-shadow: var(--shadow-lg); padding: 10px 14px; font-size: 0.88rem; max-width: 340px; }
.toast.ok { border-left: 3px solid var(--ok); }
.toast.err { border-left: 3px solid var(--danger); }

/* ---- sign-in / auth pages (SPA sign-in view + server auth pages) ---- */
.auth-page { min-height: 100vh; display: flex; align-items: center; justify-content: center; padding: 24px; background: linear-gradient(140deg, #16213e 0%, #0f3460 100%); }
.auth-card { background: var(--surface); color: var(--text); border-radius: 18px; box-shadow: var(--shadow-lg); padding: 40px 36px; max-width: 420px; width: 100%; text-align: center; }
.auth-logo { width: 72px; height: 72px; border-radius: 18px; margin-bottom: 18px; }
.auth-card h1 { font-size: 1.4rem; }
.auth-card p { color: var(--text-muted); }
.auth-sub { margin-bottom: 22px; }
.auth-btn { display: inline-flex; align-items: center; gap: 8px; justify-content: center; width: 100%; padding: 12px 16px; font-size: 1rem; }
.auth-link { font-weight: 600; }
.auth-foot { margin-top: 22px; font-size: 0.78rem; color: var(--text-faint); }
/* Emergency (break-glass) sign-in link under the Microsoft button. */
.auth-alt { margin-top: 14px; min-height: 1px; }
.auth-alt .auth-link { color: var(--danger); }
/* The break-glass form reuses .auth-card / .field / inputs; left-align its labels. */
.auth-form { text-align: left; margin-top: 8px; }
.auth-form .auth-btn { margin-top: 6px; }

/* ---- responsive: collapse the sidebar into a drawer ---- */
@media (max-width: 860px) {
  .layout { grid-template-columns: 1fr; }
  .side {
    position: fixed; left: 0; top: 0; z-index: 60; width: 86vw; max-width: 320px;
    transform: translateX(-100%); transition: transform 0.2s; visibility: hidden;
  }
  .side.open { transform: translateX(0); visibility: visible; box-shadow: var(--shadow-lg); }
  .nav-toggle { display: inline-flex; padding: 7px; border-radius: 9px; line-height: 0; }
  .nav-backdrop.show { display: block; position: fixed; inset: 0; background: rgba(0, 0, 0, 0.4); z-index: 55; }
  main { padding: 16px; }
  .topbar { padding: 12px 16px; }
}
