/*
 * SSO-specific styling, layered on top of console.css.
 *
 * console.css is copied verbatim from paywallAPI so every DryRider console looks like one
 * system; this file adds only what the launcher and the sign-in flow need. Keeping them
 * separate means console.css can be re-copied when it changes upstream without a merge.
 *
 * Palette is inherited, not redefined:
 *   background #0f1117 · panel #1a1b23 · inset #15161e · border #2a2b35
 *   accent #6366f1 · text #e4e4e7 · muted #71717a
 */

:root {
    --sso-up: #22c55e;
    --sso-degraded: #eab308;
    --sso-down: #ef4444;
    --sso-unknown: #52525b;
}

/* ------------------------------------------------------------------ launcher */

.launcher-intro {
    margin: 28px 0 20px;
}

.launcher-intro h2 {
    font-size: 20px;
    font-weight: 600;
    margin: 0 0 4px;
}

.launcher-intro p {
    color: #71717a;
    font-size: 13px;
    margin: 0;
}

.tile-grid {
    display: grid;
    grid-template-columns: repeat(auto-fill, minmax(300px, 1fr));
    gap: 16px;
    margin-bottom: 32px;
}

/*
 * The whole tile is the link. A card with a small "open" link inside it makes the click
 * target smaller than the thing that looks clickable, which is a bad trade on a page whose
 * only job is to be clicked.
 */
a.tile {
    display: block;
    background: #1a1b23;
    border: 1px solid #2a2b35;
    border-radius: 10px;
    padding: 18px;
    text-decoration: none;
    color: inherit;
    transition: border-color .15s ease, transform .15s ease;
}

a.tile:hover {
    border-color: #6366f1;
    transform: translateY(-1px);
}

a.tile:focus-visible {
    outline: 2px solid #6366f1;
    outline-offset: 2px;
}

/*
 * A DOWN tile stays clickable — the health probe can be wrong, and refusing to let someone
 * try during an incident would be exactly the wrong moment to be confident. It is dimmed,
 * not disabled.
 */
a.tile.is-down {
    opacity: .62;
}

.tile-head {
    display: flex;
    align-items: center;
    gap: 12px;
    margin-bottom: 12px;
}

.tile-icon {
    width: 34px;
    height: 34px;
    border-radius: 8px;
    background: #15161e;
    border: 1px solid #2a2b35;
    display: flex;
    align-items: center;
    justify-content: center;
    font-family: 'SF Mono', Monaco, 'Cascadia Code', monospace;
    font-size: 12px;
    font-weight: 600;
    color: #a5b4fc;
    flex-shrink: 0;
}

.tile-title {
    font-size: 15px;
    font-weight: 600;
    line-height: 1.2;
}

.tile-desc {
    color: #71717a;
    font-size: 12.5px;
    line-height: 1.5;
    margin-bottom: 14px;
    min-height: 38px;
}

.tile-meta {
    display: flex;
    align-items: center;
    justify-content: space-between;
    gap: 10px;
    padding-top: 12px;
    border-top: 1px solid #2a2b35;
    font-size: 11.5px;
    color: #71717a;
}

.tile-status {
    display: inline-flex;
    align-items: center;
    gap: 6px;
    white-space: nowrap;
}

/*
 * Colour is never the only signal. The dot carries a distinct shape per state as well —
 * a solid ring for UP, a hollow one for DEGRADED, a cross-hatched one for DOWN — so the
 * status is still readable with any form of colour vision.
 */
.status-dot {
    width: 9px;
    height: 9px;
    border-radius: 50%;
    flex-shrink: 0;
    display: inline-block;
}

.status-dot.up {
    background: var(--sso-up);
    box-shadow: 0 0 0 2px rgba(34, 197, 94, .18);
}

.status-dot.degraded {
    background: transparent;
    border: 2px solid var(--sso-degraded);
}

.status-dot.down {
    background: var(--sso-down);
    box-shadow: 0 0 0 2px rgba(239, 68, 68, .2);
}

.status-dot.unknown {
    background: transparent;
    border: 2px dashed var(--sso-unknown);
}

.tile-role {
    font-family: 'SF Mono', Monaco, 'Cascadia Code', monospace;
    font-size: 10.5px;
    letter-spacing: .04em;
    padding: 2px 7px;
    border-radius: 4px;
    background: #15161e;
    border: 1px solid #2a2b35;
    color: #a1a1aa;
}

/* ------------------------------------------------------- sign-in and failures */

.auth-card h2 {
    font-size: 17px;
    font-weight: 600;
    margin: 18px 0 6px;
}

.auth-card .subtitle {
    color: #71717a;
    font-size: 13px;
    line-height: 1.55;
    margin: 0 0 22px;
}

.btn-google {
    display: flex;
    align-items: center;
    justify-content: center;
    gap: 10px;
    width: 100%;
    padding: 11px 16px;
    font-size: 14px;
    font-weight: 500;
    color: #e4e4e7;
    background: #15161e;
    border: 1px solid #2a2b35;
    border-radius: 8px;
    cursor: pointer;
    transition: border-color .15s ease, background .15s ease;
}

.btn-google:hover:not(:disabled) {
    border-color: #6366f1;
    background: #1c1d27;
}

.btn-google:disabled {
    opacity: .55;
    cursor: progress;
}

.btn-google svg {
    width: 17px;
    height: 17px;
    flex-shrink: 0;
}

.auth-footnote {
    margin-top: 20px;
    padding-top: 16px;
    border-top: 1px solid #2a2b35;
    color: #71717a;
    font-size: 12px;
    line-height: 1.6;
}

.auth-actions {
    display: flex;
    gap: 10px;
    margin-top: 20px;
}

/* Hidden until a failure actually happens; JS toggles [hidden]. */
.notice[hidden] {
    display: none;
}

/*
 * The actionable second line of a refusal — which account to use, or the uid to hand to a
 * SUPERADMIN. Quieter than the message above it, but selectable, because a uid on screen exists
 * to be copied.
 */
.notice-hint {
    margin-top: 6px;
    font-size: 12px;
    line-height: 1.5;
    opacity: .85;
    user-select: all;
}

/* ---------------------------------------------------------- admin console bits */

.role-pill {
    font-family: 'SF Mono', Monaco, 'Cascadia Code', monospace;
    font-size: 10.5px;
    padding: 2px 7px;
    border-radius: 4px;
    border: 1px solid #2a2b35;
    background: #15161e;
    color: #a1a1aa;
    margin-right: 4px;
    white-space: nowrap;
    display: inline-block;
}

.service-role-grid {
    display: grid;
    grid-template-columns: repeat(auto-fill, minmax(220px, 1fr));
    gap: 10px;
    margin: 8px 0 16px;
}

.service-role-grid label {
    display: block;
    font-size: 12px;
    color: #a1a1aa;
    margin-bottom: 4px;
}
