/*
 * NACRE Wave 3.2 — Shared styles for the vault HTML pages.
 * Minimal, no framework, single file.
 *
 * T2525F (USER FIX 64) — the sign-in palette below is READ from the shared sign-in sheet, the same file the
 * host's inactivity lock screen links, so the two can never drift apart. Each var() keeps the value this
 * file always had as its fallback: a page whose import failed renders exactly as before.
 */
@import url('/shared/cores/theme/auth-brand.css');

* { box-sizing: border-box; }

body {
  font-family: var(--oy-auth-font, -apple-system, BlinkMacSystemFont, 'Segoe UI', sans-serif);
  /* T328 P2 (LD-1): vault auth pages share the OyOS boot gradient token
     (shared/boot-gradient.css) so login → host is background-continuous.
     Literal fallback keeps the first frame correct before the token loads. */
  background: var(--oyster-boot-gradient, linear-gradient(135deg, #0f172a 0%, #1e3a5f 50%, #0f172a 100%));
  color: var(--oy-auth-text, #e6f0f5);
  margin: 0;
  min-height: 100vh;
  display: flex;
  align-items: center;
  justify-content: center;
  padding: 24px;
  line-height: 1.5;
}

.vault-card {
  background: #18293a;
  border: 1px solid #2a3f55;
  border-radius: 12px;
  padding: 32px;
  width: 100%;
  max-width: 480px;
  box-shadow: 0 10px 30px rgba(0,0,0,0.4);
}

.vault-card h1 {
  margin: 0 0 8px 0;
  font-size: 24px;
  color: var(--oy-auth-heading, #fff);
}

.vault-card .vault-subtitle {
  color: var(--oy-auth-muted, #9fb8cb);
  font-size: 14px;
  margin: 0 0 24px 0;
}

.vault-card label {
  display: block;
  margin-top: 16px;
  margin-bottom: 6px;
  font-size: 13px;
  font-weight: 500;
  color: var(--oy-auth-label, #b8cfdf);
}

.vault-card input[type="text"],
.vault-card input[type="email"],
.vault-card input[type="password"] {
  width: 100%;
  padding: 11px 14px;
  font-size: 15px;
  background: #0e1a24;
  border: 1px solid #34495f;
  border-radius: 8px;
  color: #fff;
  font-family: inherit;
}

.vault-card input:focus {
  outline: none;
  border-color: #4dc4e0;
}

/* USER-RULED 2026-08-22 — recovery identifies an account by recovery email OR
   Login Name, and the USER picks which they typed (the page never guesses from
   the string's shape). Reuses the input palette above; no new tokens. */
.vault-card .vault-radio-group {
  margin-top: 16px;
  padding: 10px 14px 12px;
  border: 1px solid #34495f;
  border-radius: 8px;
}

.vault-card .vault-radio-group legend {
  padding: 0 6px;
  font-size: 13px;
  font-weight: 500;
  color: #b8cfdf;
}

.vault-card .vault-radio-group label {
  display: flex;
  align-items: center;
  gap: 8px;
  margin-top: 10px;
  margin-bottom: 0;
  color: #e6f1f8;
  cursor: pointer;
}

.vault-card .vault-radio-group label:first-of-type {
  margin-top: 2px;
}

.vault-card .vault-radio-group input[type="radio"] {
  accent-color: #4dc4e0;
  margin: 0;
}

.vault-btn {
  display: inline-block;
  padding: 12px 20px;
  background: #4dc4e0;
  color: #001a26;
  border: none;
  border-radius: 8px;
  font-size: 15px;
  font-weight: 600;
  cursor: pointer;
  margin-top: 24px;
  width: 100%;
  font-family: inherit;
}

.vault-btn:hover { background: #6cd5ec; }
.vault-btn:disabled { background: #34495f; color: #6a8aa3; cursor: not-allowed; }

.vault-msg {
  margin-top: 16px;
  padding: 12px 14px;
  border-radius: 8px;
  font-size: 14px;
  display: none;
}

.vault-msg.show { display: block; }
.vault-msg.error { background: var(--oy-auth-error-bg, rgba(220, 80, 80, 0.15)); color: var(--oy-auth-error-text, #ff9b9b); border: 1px solid var(--oy-auth-error-border, rgba(220, 80, 80, 0.4)); }
.vault-msg.success { background: rgba(80, 220, 130, 0.15); color: #9bff9b; border: 1px solid rgba(80, 220, 130, 0.4); }
.vault-msg.info { background: rgba(80, 180, 220, 0.15); color: #9bdfff; border: 1px solid rgba(80, 180, 220, 0.4); }

.vault-mnemonic {
  display: grid;
  grid-template-columns: repeat(3, 1fr);
  gap: 8px;
  margin: 20px 0;
  padding: 16px;
  background: #0e1a24;
  border: 1px dashed #4dc4e0;
  border-radius: 8px;
}

.vault-mnemonic-word {
  display: flex;
  flex-direction: column;
  align-items: center;
  padding: 10px 8px;
  background: #18293a;
  border-radius: 6px;
}

.vault-mnemonic-word .num {
  font-size: 11px;
  color: #6a8aa3;
  margin-bottom: 2px;
}

.vault-mnemonic-word .word {
  font-family: ui-monospace, 'SF Mono', Menlo, monospace;
  font-size: 14px;
  color: #fff;
  font-weight: 500;
}

.vault-warning {
  background: rgba(255, 200, 80, 0.12);
  border: 1px solid rgba(255, 200, 80, 0.3);
  border-radius: 8px;
  padding: 12px 14px;
  font-size: 13px;
  color: #ffd07a;
  margin: 16px 0;
}

.vault-warning strong { color: #ffe9a8; }

.vault-link {
  color: var(--oy-auth-link, #4dc4e0);
  text-decoration: none;
  font-size: 14px;
}
.vault-link:hover { text-decoration: underline; }

.vault-footer {
  margin-top: 24px;
  padding-top: 16px;
  border-top: 1px solid #2a3f55;
  text-align: center;
  font-size: 13px;
  color: #6a8aa3;
}

.vault-step { display: none; }
.vault-step.active { display: block; }

.vault-mnemonic-input {
  width: 100%;
  min-height: 100px;
  padding: 12px 14px;
  font-size: 14px;
  font-family: ui-monospace, 'SF Mono', Menlo, monospace;
  background: #0e1a24;
  border: 1px solid #34495f;
  border-radius: 8px;
  color: #fff;
  resize: vertical;
}
.vault-mnemonic-input:focus { outline: none; border-color: #4dc4e0; }

/* T2469F P1 (FIX 24) — 12 per-word recovery-phrase boxes. 3×4 on desktop, 2×6 on
   a phone. Each box is a masked input with its number beside it; ONE toggle
   (#toggle-words) reveals them all. Palette = the input palette above. */
.vault-phrase-head {
  display: flex;
  align-items: center;
  justify-content: space-between;
  gap: 12px;
  margin-top: 16px;
}
.vault-phrase-head label { margin: 0; }
.vault-phrase-hint {
  margin: 6px 0 0;
  font-size: 12px;
  color: #6a8aa3;
}
.vault-phrase-boxes {
  display: grid;
  grid-template-columns: repeat(3, minmax(0, 1fr));
  gap: 8px;
  margin: 10px 0 4px;
  padding: 12px;
  background: #0e1a24;
  border: 1px dashed #4dc4e0;
  border-radius: 8px;
}
@media (max-width: 480px) {
  .vault-phrase-boxes { grid-template-columns: repeat(2, minmax(0, 1fr)); }
}
/* `.vault-card label` (above) is display:block with a top margin; the cell is a
   <label> so it must out-rank that rule, or the number stacks above the input and
   the input keeps its intrinsic width (measured on a 390px phone: overflow). */
.vault-card .vault-word {
  display: flex;
  align-items: center;
  gap: 6px;
  margin: 0;
  min-width: 0;
}
.vault-card .vault-word-num {
  flex: 0 0 18px;
  text-align: right;
  font-size: 11px;
  color: #6a8aa3;
  font-variant-numeric: tabular-nums;
}
.vault-card .vault-word-input,
.vault-card input.vault-word-input[type="password"],
.vault-card input.vault-word-input[type="text"] {
  flex: 1 1 0%;
  min-width: 0;
  width: 0;
  padding: 9px 10px;
  font-size: 14px;
  font-family: ui-monospace, 'SF Mono', Menlo, monospace;
  background: #18293a;
  border: 1px solid #34495f;
  border-radius: 6px;
  color: #fff;
  text-align: left;
}
.vault-card .vault-word-input[aria-invalid="true"] {
  border-color: #ff9b9b;
  box-shadow: 0 0 0 1px rgba(220, 80, 80, 0.4);
}
.vault-toggle {
  flex: 0 0 auto;
  padding: 6px 10px;
  font-size: 12px;
  font-weight: 500;
  color: #4dc4e0;
  background: transparent;
  border: 1px solid #34495f;
  border-radius: 6px;
  cursor: pointer;
  font-family: inherit;
}
.vault-toggle:hover, .vault-toggle:focus-visible { border-color: #4dc4e0; outline: none; }
.vault-toggle[aria-pressed="true"] { background: rgba(77, 196, 224, 0.14); }

/* T2469F P4 — password reveal ("eye"). The button sits inside the field's
   right edge; the input keeps room for it. `data-reveal-for` is wired by
   /auth/password-reveal.js — no per-page JS. */
.vault-pw-wrap { position: relative; }
.vault-card .vault-pw-wrap input[type="password"],
.vault-card .vault-pw-wrap input[type="text"] { padding-right: 46px; }
.vault-eye {
  position: absolute;
  top: 50%;
  right: 8px;
  transform: translateY(-50%);
  width: 32px;
  height: 32px;
  padding: 0;
  display: inline-flex;
  align-items: center;
  justify-content: center;
  color: #6a8aa3;
  background: transparent;
  border: 0;
  border-radius: 6px;
  cursor: pointer;
}
.vault-eye:hover, .vault-eye:focus-visible { color: #4dc4e0; outline: none; background: rgba(77, 196, 224, 0.12); }
.vault-eye svg { width: 20px; height: 20px; display: block; }
.vault-eye .eye-off { display: none; }
.vault-eye.is-revealed .eye-on { display: none; }
.vault-eye.is-revealed .eye-off { display: block; }

/* T2469F P2 — the two recovery options on one screen. */
.vault-choice {
  display: block;
  width: 100%;
  margin-top: 12px;
  padding: 14px 16px;
  text-align: left;
  background: #0e1a24;
  border: 1px solid #34495f;
  border-radius: 8px;
  color: #fff;
  cursor: pointer;
  font-family: inherit;
}
.vault-choice:hover, .vault-choice:focus-visible { border-color: #4dc4e0; outline: none; }
.vault-choice strong { display: block; font-size: 15px; color: #fff; }
.vault-choice span { display: block; margin-top: 4px; font-size: 13px; color: #b8cfdf; }
.vault-other-option { margin-top: 14px; font-size: 13px; color: #b8cfdf; }

/* T403 P7 (LD-11): glass degrade on prefers-reduced-transparency.
   Login page uses the boot gradient token; collapse glass alpha to solid
   when the OS accessibility setting is active — matches boot-gradient.css rule. */
@media (prefers-reduced-transparency: reduce) {
  body {
    /* Collapse to a solid navy background — no translucency */
    background: #0f172a;
  }
  .vault-card {
    background: #18293a;
    box-shadow: none;
  }
}
