:root {
    --gb-bg: #f7f5f2;
    --gb-surface: #ffffff;
    --gb-text: #1c1917;
    --gb-muted: #78716c;
    --gb-border: #e7e2dc;
    --gb-accent: #b8860b;
    --gb-accent-hover: #9a710a;
    --gb-danger: #b42318;
    --gb-radius: 12px;
}

html {
    font-size: 16px;
}

body {
    min-height: 100vh;
    margin: 0;
    background-color: var(--gb-bg);
    color: var(--gb-text);
    font-family: ui-sans-serif, system-ui, -apple-system, "Segoe UI", Roboto, "Helvetica Neue", Arial, sans-serif;
    -webkit-font-smoothing: antialiased;
}

/* Layout: one centered card. Every page in this app is a single task. */

.auth-shell {
    min-height: 100vh;
    display: flex;
    flex-direction: column;
    align-items: center;
    justify-content: center;
    padding: 2rem 1rem;
}

.auth-card {
    width: 100%;
    max-width: 26rem;
    background: var(--gb-surface);
    border: 1px solid var(--gb-border);
    border-radius: var(--gb-radius);
    padding: 2.25rem 2rem;
    box-shadow: 0 1px 2px rgba(28, 25, 23, .04), 0 8px 24px rgba(28, 25, 23, .06);
}

.auth-brand {
    display: block;
    margin-bottom: 1.75rem;
    color: var(--gb-text);
    font-size: 1.25rem;
    font-weight: 650;
    letter-spacing: -.01em;
    text-decoration: none;
}

.auth-brand::after {
    content: "";
    display: block;
    width: 1.75rem;
    height: 3px;
    margin-top: .5rem;
    border-radius: 2px;
    background: var(--gb-accent);
}

.auth-legal {
    margin: 1.5rem 0 0;
    color: var(--gb-muted);
    font-size: .8125rem;
}

/* Typography inside the card */

.auth-card h1, .auth-card h2 {
    margin: 0 0 1.25rem;
    font-size: 1.375rem;
    font-weight: 620;
    letter-spacing: -.01em;
}

.auth-card h2 {
    font-size: 1.0625rem;
}

/* The packaged Identity pages label their form sections with <h2>Use a local
   account to log in.</h2> and similar. The heading above already says it. */
.auth-card form > h2,
.auth-card section > h2 {
    display: none;
}

.auth-card h3 {
    font-size: .9375rem;
    font-weight: 600;
    color: var(--gb-muted);
}

.auth-card p {
    color: var(--gb-muted);
    font-size: .9375rem;
    line-height: 1.55;
}

/* Identity's forms open with a divider directly under the page heading, which
   reads as noise once the card already separates the content. */
.auth-card form > hr:first-of-type {
    display: none;
}

.auth-card hr {
    margin: 1.5rem 0;
    border-color: var(--gb-border);
    opacity: 1;
}

/* The secondary links below the submit button (forgot password, register,
   resend confirmation) are navigation, not calls to action. */
.auth-card form > div > p,
.auth-card form > p {
    margin-bottom: .375rem;
    font-size: .875rem;
}

.auth-card form > div > p a,
.auth-card form > p a {
    color: var(--gb-muted);
    text-decoration: none;
}

.auth-card form > div > p a:hover {
    color: var(--gb-accent);
    text-decoration: underline;
}

a {
    color: var(--gb-accent);
    text-underline-offset: 2px;
}

a:hover {
    color: var(--gb-accent-hover);
}

/* Identity's pages lay their forms out in Bootstrap grid columns sized for a
   full-width page (col-md-4 and friends). Inside a narrow card those collapse
   to a third of the width, so force the columns to stack full width. */
.auth-card .row {
    margin: 0;
}

.auth-card .row > [class*="col-"] {
    flex: 0 0 100%;
    width: 100%;
    max-width: 100%;
    padding: 0;
}

/* Hides the "Use another service to log in" column, which currently renders
   only the message that no external providers are configured. Remove this rule
   if Google or GitHub sign-in is ever added. */
.auth-card .row > div:nth-child(2) {
    display: none;
}

/* Form controls */

.form-floating > label,
.form-label {
    color: var(--gb-muted);
    font-size: .9375rem;
}

.form-control {
    padding: .625rem .75rem;
    border: 1px solid var(--gb-border);
    border-radius: 8px;
    background-color: var(--gb-surface);
    color: var(--gb-text);
    font-size: .9375rem;
}

.form-control:focus {
    border-color: var(--gb-accent);
    box-shadow: 0 0 0 3px rgba(184, 134, 11, .15);
}

.form-floating {
    margin-bottom: .875rem;
}

.form-check-input:checked {
    background-color: var(--gb-accent);
    border-color: var(--gb-accent);
}

.form-check-input:focus {
    border-color: var(--gb-accent);
    box-shadow: 0 0 0 3px rgba(184, 134, 11, .15);
}

.form-check-label {
    color: var(--gb-muted);
    font-size: .9375rem;
}

/* Buttons */

.btn {
    border-radius: 8px;
    font-size: .9375rem;
    font-weight: 550;
    padding: .625rem 1rem;
}

.btn-primary,
.btn-lg.btn-primary {
    background-color: var(--gb-accent);
    border-color: var(--gb-accent);
    color: #fff;
}

.btn-primary:hover,
.btn-primary:focus,
.btn-primary:active {
    background-color: var(--gb-accent-hover);
    border-color: var(--gb-accent-hover);
    color: #fff;
}

.btn:focus-visible {
    box-shadow: 0 0 0 3px rgba(184, 134, 11, .25);
}

.btn-danger {
    background-color: var(--gb-danger);
    border-color: var(--gb-danger);
}

/* Validation */

.text-danger,
.validation-summary-errors {
    color: var(--gb-danger) !important;
    font-size: .875rem;
}

.validation-summary-errors ul {
    margin: 0 0 1rem;
    padding-left: 1.125rem;
}

.field-validation-error {
    display: block;
    margin-top: .25rem;
}

/* Identity's account-management pages use a nav-pills sidebar. */

.nav-pills .nav-link {
    color: var(--gb-muted);
}

.nav-pills .nav-link.active,
.nav-pills .show > .nav-link {
    background-color: var(--gb-accent);
    color: #fff;
}
