/* ── Login-family pages ──
   Shared sheet for two_factor/_base.html (login, 2FA setup, setup complete)
   and auth/password_change.html. Loads after tokens.css; does not extend
   app.css. Page-specific sections are grouped at the bottom. */

* { box-sizing: border-box; margin: 0; padding: 0; }

body {
  font-family: var(--font-family);
  background: var(--light-grey);
  color: var(--text-primary);
  min-height: 100vh;
  display: flex;
  align-items: center;
  justify-content: center;
  padding: 40px 20px;
}

.card {
  background: var(--white);
  border: 1px solid var(--border);
  border-radius: var(--panel-radius);
  padding: 44px 40px;
  width: 100%;
  max-width: 400px;
  text-align: center;
  box-shadow: 0 4px 24px rgba(15, 23, 42, 0.04);
}

.logo-btn { display: flex; align-items: center; justify-content: center; }

.logo-img { height: 44px; width: auto; display: block; }

.welcome {
  font-size: var(--fs-13);
  color: var(--text-secondary);
  margin: 24px 0 28px;
  font-weight: var(--fw-medium);
}

.field {
  margin-bottom: 16px;
  text-align: left;
}

.field label {
  display: block;
  font-size: var(--fs-11);
  font-weight: var(--fw-semibold);
  letter-spacing: 0.04em;
  text-transform: uppercase;
  color: var(--text-secondary);
  margin-bottom: 6px;
}

.field input {
  width: 100%;
  padding: 12px 14px;
  border: 1px solid var(--border);
  border-radius: var(--radius);
  font-family: var(--font-family);
  font-size: var(--fs-14);
  color: var(--text-primary);
  background: var(--white);
  transition: all 0.15s;
}

.field input:focus {
  outline: none;
  border-color: var(--red-accent);
  box-shadow: var(--ring-halo);
}

.field input::placeholder { color: var(--text-tertiary); font-size: var(--fs-11); }

.error-list {
  background: var(--red-light);
  border: 1px solid var(--red-pale);
  border-radius: var(--radius);
  padding: 10px 14px;
  margin-bottom: 16px;
  text-align: left;
}

.error-list p {
  font-size: var(--fs-12);
  color: var(--red-accent);
  font-weight: var(--fw-semibold);
}

.btn-signin {
  width: 100%;
  padding: 13px;
  background: var(--red-accent);
  color: var(--white);
  border: none;
  border-radius: var(--radius);
  font-family: var(--font-family);
  font-size: var(--fs-13);
  font-weight: var(--fw-bold);
  letter-spacing: 1px;
  text-transform: uppercase;
  cursor: pointer;
  transition: all 0.15s;
  margin-top: 4px;
}

.btn-signin:hover { background: var(--red-accent-dark); }

/* Per-field error box, under the input it belongs to. */
.field .error-list { margin-top: 8px; margin-bottom: 0; }

/* Body copy on the setup pages. */
.prose {
  font-size: var(--fs-13);
  color: var(--text-secondary);
  line-height: 1.5;
  text-align: left;
  margin-bottom: 20px;
}

/* setup_complete.html renders .btn-signin as an <a>. */
.btn-signin--link { display: block; text-align: center; text-decoration: none; }

/* Secondary escape hatch ("Sign out instead"). */
.btn-back {
  display: block;
  width: 100%;
  margin-top: 16px;
  padding: 0;
  background: none;
  border: none;
  font-family: var(--font-family);
  font-size: var(--fs-12);
  font-weight: var(--fw-medium);
  color: var(--text-secondary);
  text-decoration: none;
  cursor: pointer;
  transition: color 0.15s;
}

.btn-back:hover { color: var(--red-accent); }

/* ── two_factor pages only ── */

/* The setup step's token field is <input type="number">; hide the spin
   buttons so it reads as a plain code box (Chrome/Safari/Edge + Firefox). */
.field input[type="number"] { -moz-appearance: textfield; appearance: textfield; }
.field input[type="number"]::-webkit-outer-spin-button,
.field input[type="number"]::-webkit-inner-spin-button {
  -webkit-appearance: none;
  margin: 0;
}

.qr { display: flex; justify-content: center; margin: 8px 0 20px; }
.qr img { width: 200px; height: 200px; }

.secret {
  font-size: var(--fs-12);
  color: var(--text-secondary);
  word-break: break-all;
  background: var(--light-grey);
  border: 1px solid var(--border);
  border-radius: var(--btn-radius);
  padding: 8px 10px;
  margin-bottom: 16px;
}

/* 6-digit entry (login token step + setup generator step) */
.otp-field { text-align: center; }
.otp-group { display: flex; gap: 8px; justify-content: center; margin: 4px 0 6px; }

.otp-box {
  width: 44px;
  height: 52px;
  border: 1px solid var(--border);
  border-radius: var(--radius);
  font-family: var(--font-family);
  font-size: var(--fs-20);
  font-weight: var(--fw-semibold);
  text-align: center;
  color: var(--text-primary);
  background: var(--white);
  transition: all 0.15s;
}

.otp-box:focus {
  outline: none;
  border-color: var(--red-accent);
  box-shadow: var(--ring-halo);
}

/* The real token field: reachable by label and by validation, off-screen for
   the eye. Not type=hidden — Django's error rendering needs a real widget. */
.otp-real-wrap {
  position: absolute;
  width: 1px; height: 1px;
  padding: 0; margin: -1px;
  overflow: hidden;
  clip: rect(0, 0, 0, 0);
  white-space: nowrap;
  border: 0;
}

@media (max-width: 600px) {
  .card { padding: 36px 28px; }
  .otp-box { width: 40px; height: 48px; font-size: var(--fs-18); }
}
