/* TACPTT2 web console. System fonts only, no external resources. Colours are tokens; dark follows the system unless the toggle says otherwise. */
:root {
  --bg: #f1f3f5; --panel: #ffffff; --panel2: #f6f7f9; --border: #d3d8de; --text: #1b1f24; --muted: #596470;
  --accent: #1a62d6; --accent-text: #ffffff; --ok: #1d8a4b; --bad: #c62a2f; --warn: #b05a00; --focus: #1a62d6;
  --c-allow: #b7e4c7; --c-allow-inh: #dcf2e3; --c-deny: #f5b5b8; --c-deny-inh: #fbd9db; --c-over: #fbd5a0; --c-none: #e4e7eb;
  --sel: #dbe8fd; --shadow: 0 1px 2px rgba(0,0,0,.08);
  --font: system-ui, -apple-system, "Segoe UI", Roboto, "Helvetica Neue", Arial, sans-serif; --mono: ui-monospace, Consolas, "SFMono-Regular", Menlo, monospace;
  color-scheme: light;
}
@media (prefers-color-scheme: dark) {
  :root:not([data-theme="light"]) {
    --bg: #101317; --panel: #181c22; --panel2: #1e232a; --border: #2d353e; --text: #e6e9ed; --muted: #98a3ae;
    --accent: #4d8dff; --accent-text: #0b1220; --ok: #3aa766; --bad: #e5484d; --warn: #ff9f1a; --focus: #7aa7ff;
    --c-allow: #1f5d3a; --c-allow-inh: #1a3f2c; --c-deny: #7a2a2e; --c-deny-inh: #4d2528; --c-over: #6b4a14; --c-none: #232930;
    --sel: #1f3358; --shadow: none; color-scheme: dark;
  }
}
:root[data-theme="dark"] {
  --bg: #101317; --panel: #181c22; --panel2: #1e232a; --border: #2d353e; --text: #e6e9ed; --muted: #98a3ae;
  --accent: #4d8dff; --accent-text: #0b1220; --ok: #3aa766; --bad: #e5484d; --warn: #ff9f1a; --focus: #7aa7ff;
  --c-allow: #1f5d3a; --c-allow-inh: #1a3f2c; --c-deny: #7a2a2e; --c-deny-inh: #4d2528; --c-over: #6b4a14; --c-none: #232930;
  --sel: #1f3358; --shadow: none; color-scheme: dark;
}

*, *::before, *::after { box-sizing: border-box; }
html { font-size: 15px; }
body { margin: 0; background: var(--bg); color: var(--text); font-family: var(--font); line-height: 1.45; }
h1 { font-size: 1.45rem; margin: 0 0 .8rem; }
h2 { font-size: 1.08rem; margin: 0 0 .6rem; }
h3 { font-size: .98rem; margin: 1rem 0 .4rem; }
p { margin: .4rem 0; }
a { color: var(--accent); }
a.rowlink { text-decoration: none; font-weight: 600; }
a.rowlink:hover { text-decoration: underline; }
:focus-visible { outline: 3px solid var(--focus); outline-offset: 2px; }
[hidden] { display: none !important; }
.sr { position: absolute; width: 1px; height: 1px; overflow: hidden; clip: rect(0 0 0 0); white-space: nowrap; }
.skip { position: absolute; left: -999px; top: 0; background: var(--accent); color: var(--accent-text); padding: .5rem 1rem; z-index: 100; }
.skip:focus { left: 0; }
.muted { color: var(--muted); }
.num { text-align: right; font-variant-numeric: tabular-nums; }
.hint { color: var(--muted); font-size: .85rem; margin-top: .25rem; }
.error-text { color: var(--bad); font-weight: 600; }
.warn-text { color: var(--warn); font-weight: 600; }
.note { background: var(--panel2); border: 1px solid var(--border); border-radius: 6px; padding: .5rem .75rem; }
ul.plain { margin: .3rem 0; padding-left: 1.2rem; }
pre.explain, pre.result { white-space: pre-wrap; font-family: var(--font); font-size: .9rem; margin: .4rem 0; background: var(--panel2); border: 1px solid var(--border); border-radius: 6px; padding: .5rem .75rem; }
pre.result:empty { display: none; }
.noscript { padding: 1rem; background: var(--bad); color: #fff; }

/* buttons and form controls */
.btn, button.btn, a.btn { display: inline-block; font: inherit; font-size: .92rem; padding: .42rem .85rem; border-radius: 6px; border: 1px solid var(--border); background: var(--panel2); color: var(--text); cursor: pointer; text-decoration: none; min-height: 34px; }
.btn:hover:not(:disabled) { border-color: var(--accent); }
.btn:disabled { opacity: .5; cursor: not-allowed; }
.btn.primary { background: var(--accent); color: var(--accent-text); border-color: var(--accent); font-weight: 600; }
.btn.danger { background: var(--bad); color: #fff; border-color: var(--bad); font-weight: 600; }
.btn.small { padding: .25rem .6rem; min-height: 28px; font-size: .85rem; }
.btn.wide { width: 100%; }
.btn-row { display: flex; flex-wrap: wrap; gap: .5rem; margin: .6rem 0; }
input[type=text], input[type=search], input[type=password], input[type=date], input[type=datetime-local], select { font: inherit; font-size: .92rem; padding: .4rem .55rem; border: 1px solid var(--border); border-radius: 6px; background: var(--panel); color: var(--text); min-height: 34px; width: 100%; max-width: 100%; }
input:disabled, select:disabled { opacity: .55; }
input[type=checkbox] { width: 1.1rem; height: 1.1rem; accent-color: var(--accent); vertical-align: middle; }
label.check { display: inline-flex; gap: .5rem; align-items: center; cursor: pointer; margin: .2rem .8rem .2rem 0; }
.field { display: flex; flex-direction: column; gap: .2rem; min-width: 150px; flex: 1 1 170px; }
.field label { font-size: .85rem; color: var(--muted); font-weight: 600; }
.form-row { display: flex; flex-wrap: wrap; gap: .75rem; align-items: flex-end; margin: .4rem 0; }
.actions-field { flex: 0 0 auto; min-width: 0; }
.toolbar { display: flex; flex-wrap: wrap; gap: .75rem; align-items: center; margin-bottom: .6rem; }
.toolbar input[type=search] { max-width: 280px; }
fieldset { border: 1px solid var(--border); border-radius: 8px; margin: .6rem 0; padding: .4rem .8rem .6rem; }
legend { padding: 0 .4rem; font-weight: 600; }

/* shell */
.top { display: flex; align-items: center; gap: .75rem; flex-wrap: wrap; padding: .5rem 1rem; background: var(--panel); border-bottom: 1px solid var(--border); position: sticky; top: 0; z-index: 20; }
.brand { font-weight: 700; }
.spacer { flex: 1; }
.who { color: var(--muted); }
.status { color: var(--muted); font-size: .85rem; }
.status.bad { color: var(--bad); font-weight: 600; }
.status.warn { color: var(--warn); font-weight: 600; }
.devbadge { background: var(--warn); color: #000; padding: .1rem .5rem; border-radius: 4px; font-weight: 700; font-size: .8rem; }
.shell { display: flex; align-items: flex-start; }
#nav { width: 200px; flex: 0 0 200px; padding: .75rem .5rem; position: sticky; top: 49px; align-self: flex-start; }
#nav ul { list-style: none; margin: 0; padding: 0; }
#nav a { display: block; padding: .5rem .8rem; border-radius: 6px; color: var(--text); text-decoration: none; }
#nav a:hover { background: var(--panel2); }
#nav a[aria-current=page] { background: var(--accent); color: var(--accent-text); font-weight: 600; }
#main { flex: 1; min-width: 0; padding: 1rem 1.25rem 3rem; outline: none; }
.page { max-width: 1250px; }
.card { background: var(--panel); border: 1px solid var(--border); border-radius: 10px; padding: .85rem 1rem; margin-bottom: 1rem; box-shadow: var(--shadow); }
.two-col { display: grid; grid-template-columns: minmax(0, 1fr) minmax(0, 1fr); gap: 1rem; align-items: start; }
.two-col.wide-left { grid-template-columns: minmax(0, 1.2fr) minmax(0, 1fr); }
.two-col > div > .card:last-child { margin-bottom: 1rem; }

/* tables */
.table-wrap { overflow-x: auto; max-width: 100%; }
.tbl { border-collapse: collapse; width: 100%; font-size: .92rem; }
.tbl th, .tbl td { text-align: left; padding: .4rem .6rem; border-bottom: 1px solid var(--border); vertical-align: middle; }
.tbl th { color: var(--muted); font-size: .8rem; text-transform: none; font-weight: 700; white-space: nowrap; }
.tbl td.num, .tbl th.num { text-align: right; }
.tbl td.empty { color: var(--muted); text-align: center; padding: 1rem; }
.tbl tr[tabindex] { cursor: pointer; }
.tbl tr:hover td { background: var(--panel2); }
.tbl tr.sel td { background: var(--sel); }
.tbl tr.removed td, .tbl tr.revoked td { color: var(--muted); }
.tbl td.detail { font-family: var(--mono); font-size: .8rem; word-break: break-all; max-width: 420px; }
.tbl td.actions { white-space: nowrap; text-align: right; }
.row-actions { display: flex; gap: .3rem; flex-wrap: wrap; justify-content: flex-end; }
.row-actions .btn { padding: .2rem .55rem; min-height: 28px; font-size: .85rem; }
.pill { display: inline-block; padding: .05rem .5rem; border-radius: 999px; font-size: .8rem; font-weight: 600; border: 1px solid var(--border); margin-right: .3rem; }
.pill.ok { color: var(--ok); border-color: var(--ok); } .pill.bad { color: var(--bad); border-color: var(--bad); } .pill.warn { color: var(--warn); border-color: var(--warn); }
.pill.muted-pill { color: var(--muted); }
.on { color: var(--ok); font-weight: 600; }

/* matrix */
.matrix th.colh { white-space: normal; min-width: 92px; max-width: 120px; text-align: center; vertical-align: bottom; }
.matrix td.mcell { text-align: center; font-size: .82rem; cursor: pointer; border: 1px solid var(--bg); min-width: 92px; }
.matrix .stick { position: sticky; left: 0; background: var(--panel); z-index: 2; min-width: 110px; }
.c-allow { background: var(--c-allow); } .c-allow-inh { background: var(--c-allow-inh); } .c-deny { background: var(--c-deny); font-weight: 700; }
.c-deny-inh { background: var(--c-deny-inh); } .c-over { background: var(--c-over); } .c-none { background: var(--c-none); color: var(--muted); }
.matrix td.mcell.sel { outline: 3px solid var(--focus); outline-offset: -3px; }
.matrix tr:hover td.mcell { background-clip: padding-box; }
.legend-chips { display: inline-flex; flex-wrap: wrap; gap: .4rem; }
.chip { padding: .1rem .5rem; border-radius: 4px; font-size: .8rem; }

/* the permissions grid editor */
.editor-head { display: flex; align-items: baseline; gap: 1rem; flex-wrap: wrap; }
.editor-head .back { text-decoration: none; }
.legend { color: var(--muted); font-size: .88rem; }
.grid { table-layout: fixed; }
.grid th:first-child { width: 28%; }
.grid td.cellbox { padding: .3rem .6rem; }
.grid .chname { font-weight: 500; white-space: normal; overflow-wrap: anywhere; }
.grid tr.allrow th, .grid tr.allrow td { background: var(--panel2); font-weight: 700; }
.grid tr.note-row td { color: var(--muted); font-size: .82rem; padding: .25rem .6rem; }
.cellwrap { display: flex; align-items: center; gap: .55rem; min-height: 32px; }
.tri { width: 28px; height: 28px; flex: 0 0 28px; border-radius: 6px; border: 2px solid var(--muted); background: var(--panel); color: #fff; font-size: 1rem; line-height: 1; font-weight: 700; cursor: pointer; padding: 0; display: inline-flex; align-items: center; justify-content: center; }
.tri[data-state=allow] { background: var(--ok); border-color: var(--ok); }
.tri[data-state=blocked] { background: var(--bad); border-color: var(--bad); }
.tri.changed { box-shadow: 0 0 0 3px var(--focus); }
.tri.overridden { border-color: var(--warn); box-shadow: 0 0 0 3px var(--warn); }
.via { font-size: .78rem; color: var(--muted); }
.via.warn { color: var(--warn); font-weight: 700; }
.via.bad { color: var(--bad); }
.tenant-grid { display: grid; grid-template-columns: repeat(auto-fill, minmax(290px, 1fr)); gap: .5rem 1.2rem; }
.tenant-item { display: grid; grid-template-columns: 28px 1fr; gap: .1rem .6rem; align-items: center; cursor: pointer; padding: .2rem 0; }
.tenant-item .via { grid-column: 2; margin-top: -.15rem; }
.own-opt { margin: .1rem 0 .4rem 2.2rem; }
.own-opt.unsupported { opacity: .6; }
.admin-items { margin-top: .8rem; } .admin-items summary { cursor: pointer; font-weight: 600; margin-bottom: .5rem; }
.savebar { position: sticky; bottom: 0; display: flex; justify-content: space-between; align-items: center; gap: 1rem; flex-wrap: wrap; padding: .6rem 1rem; background: var(--panel); border: 1px solid var(--border); border-radius: 10px; }
.savebar .count { font-weight: 600; }
.savebar .btn-row { margin: 0; }

/* config */
.cfg-section .cfg-grid { display: grid; grid-template-columns: repeat(auto-fill, minmax(190px, 1fr)); gap: .5rem .9rem; }

/* usage chart */
.chart { width: 100%; height: auto; display: block; }
.chart .bar { fill: var(--accent); } .chart .bar-b { fill: var(--ok); }
.chart text { fill: var(--text); font-size: 12px; font-family: var(--font); } .chart .ct-value { fill: var(--muted); }

/* dialogs and toasts */
dialog.dlg { border: 1px solid var(--border); border-radius: 12px; padding: 0; background: var(--panel); color: var(--text); width: min(560px, calc(100vw - 2rem)); max-height: calc(100vh - 2rem); box-shadow: 0 10px 40px rgba(0,0,0,.35); }
dialog.dlg::backdrop { background: rgba(0,0,0,.5); }
dialog.dlg form, dialog.dlg .dlg-form { padding: 1rem 1.25rem; margin: 0; }
dialog.dlg h2 { margin-top: 0; }
.dlg-body { max-height: 55vh; overflow: auto; }
.dlg-body p { margin: .25rem 0; } .dlg-body p.indent { padding-left: 1rem; } .dlg-body .gap { height: .5rem; }
.dlg-actions { display: flex; justify-content: flex-end; gap: .6rem; margin-top: 1rem; }
.toasts { position: fixed; right: 1rem; bottom: 1rem; display: flex; flex-direction: column; gap: .5rem; z-index: 200; width: min(440px, calc(100vw - 2rem)); }
.toast { display: flex; gap: .5rem; padding: .6rem .8rem; border-radius: 8px; background: var(--panel); border: 1px solid var(--border); border-left: 5px solid var(--ok); box-shadow: 0 4px 16px rgba(0,0,0,.25); }
.toast.warn { border-left-color: var(--warn); } .toast.error { border-left-color: var(--bad); }
.toast-text { flex: 1; min-width: 0; overflow-wrap: anywhere; } .toast-detail { color: var(--muted); font-size: .82rem; margin-top: .15rem; }
.toast-x { background: none; border: 0; color: var(--muted); font-size: 1.3rem; cursor: pointer; line-height: 1; }

/* sign-in */
#login { min-height: 100vh; display: flex; align-items: center; justify-content: center; padding: 1rem; }
.login-card { width: min(380px, 100%); background: var(--panel); border: 1px solid var(--border); border-radius: 12px; padding: 1.4rem; display: flex; flex-direction: column; gap: .8rem; box-shadow: var(--shadow); }
.login-card h1 { margin: 0; }
.login-banner { background: var(--panel2); border: 1px solid var(--warn); border-radius: 6px; padding: .5rem .7rem; margin: 0; }
.login-msg { color: var(--bad); font-weight: 600; margin: 0; min-height: 1.2em; }

/* narrow screens: the menu becomes a row on top; tables become stacked cards (except the matrix and the permissions grid) */
@media (max-width: 860px) {
  .shell { flex-direction: column; }
  #nav { width: 100%; flex: none; position: static; padding: .4rem .5rem 0; overflow-x: auto; }
  #nav ul { display: flex; gap: .3rem; white-space: nowrap; }
  #nav a { padding: .4rem .7rem; border: 1px solid var(--border); }
  #main { padding: .8rem 1rem 3rem; width: 100%; }
  .two-col, .two-col.wide-left { grid-template-columns: minmax(0, 1fr); }
  .top { padding: .4rem .75rem; } .devbadge { flex-basis: 100%; }
}
@media (max-width: 640px) {
  html { font-size: 14.5px; }
  .tbl:not(.matrix):not(.grid) thead { position: absolute; width: 1px; height: 1px; overflow: hidden; clip: rect(0 0 0 0); }
  .tbl:not(.matrix):not(.grid), .tbl:not(.matrix):not(.grid) tbody, .tbl:not(.matrix):not(.grid) tr, .tbl:not(.matrix):not(.grid) td { display: block; width: 100%; }
  .tbl:not(.matrix):not(.grid) tr { border: 1px solid var(--border); border-radius: 8px; margin-bottom: .6rem; padding: .3rem .2rem; }
  .tbl:not(.matrix):not(.grid) td { border: 0; padding: .15rem .6rem; text-align: left; display: flex; gap: .6rem; justify-content: space-between; }
  .tbl:not(.matrix):not(.grid) td::before { content: attr(data-label); color: var(--muted); font-size: .78rem; font-weight: 700; flex: 0 0 38%; }
  .tbl:not(.matrix):not(.grid) td.actions, .tbl:not(.matrix):not(.grid) td.empty { display: block; text-align: left; }
  .tbl:not(.matrix):not(.grid) td.actions::before, .tbl:not(.matrix):not(.grid) td.empty::before { content: none; }
  .row-actions { justify-content: flex-start; }
  .grid th:first-child { width: 24%; }
  .cellwrap { flex-direction: column; align-items: flex-start; gap: .15rem; }
  .grid td.cellbox, .grid th { padding: .3rem .3rem; }
  .tenant-grid { grid-template-columns: 1fr; }
  .tri { width: 32px; height: 32px; flex-basis: 32px; }
  .toasts { left: 1rem; right: 1rem; width: auto; }
}
@media (prefers-reduced-motion: reduce) { * { scroll-behavior: auto !important; transition: none !important; animation: none !important; } }

.login-card .field, .pw-form .field, .dlg-form .field { flex: none; }
.pw-form { display: flex; flex-direction: column; gap: .6rem; }
.secret-key { font-family: var(--mono); font-size: 1.05rem; word-break: break-all; user-select: all; }

/* device permissions grid: read-only boxes; where a result comes from */
.tri.ro { cursor: default; }
.via.origin-shared, .via.origin-mixed { font-style: italic; }
