:root {
    --ground: #f6f7fa;
    --surface: #ffffff;
    --surface-2: #eff1f6;
    --ink: #14171d;
    --muted: #5c6577;
    --rule: #d9dee7;
    --accent: #2d53c8;
    --accent-soft: #e6ebfa;
    --danger: #b32d1b;
    --danger-soft: #fbe9e6;
    --ok: #0f7a6b;
    --ok-soft: #e2f2ef;
    --sidebar: #fbfbfc;
    --sidebar-hover: #eef0f4;
    --sidebar-active: #e4e7ed;
    --sidebar-w: 16.5rem;
    --sidebar-rail-w: 3.75rem;
}

* { box-sizing: border-box; }

body {
    margin: 0;
    background: var(--ground);
    color: var(--ink);
    font: 15px/1.6 system-ui, -apple-system, "Segoe UI", sans-serif;
}

code {
    font-family: ui-monospace, Consolas, monospace;
    font-size: 0.9em;
    background: var(--surface-2);
    border: 1px solid var(--rule);
    border-radius: 3px;
    padding: 0.1em 0.35em;
}

/* ---- shell ---- */

.app { display: flex; min-height: 100vh; }

/* The sidebar holds its own scroll: it is pinned to the viewport height, the
   links scroll inside .nav-body, and the account card stays at the bottom no
   matter how long the page beside it is. */
.sidebar {
    width: var(--sidebar-w);
    flex: 0 0 var(--sidebar-w);
    position: sticky;
    top: 0;
    height: 100vh;
    align-self: flex-start;
    background: var(--sidebar);
    border-right: 1px solid var(--rule);
    transition: width 0.15s ease, flex-basis 0.15s ease;
}

.sidebar:has(> .nav--collapsed) { width: var(--sidebar-rail-w); flex-basis: var(--sidebar-rail-w); }

.content { flex: 1; min-width: 0; padding: 2rem clamp(1rem, 4vw, 3rem); max-width: 68rem; }

/* ---- nav ---- */

.nav {
    display: flex;
    flex-direction: column;
    height: 100%;
    font-size: 0.9rem;
}

/* Every control in the nav is a quiet row, not the app's filled accent
   button — the global `button` rule would otherwise paint each one blue. */
.nav button {
    font: inherit;
    font-weight: inherit;
    color: inherit;
    background: none;
    border: 0;
    padding: 0;
    cursor: pointer;
}

.nav :is(a, button):focus-visible { outline: 2px solid var(--accent); outline-offset: 1px; }

.nav-icon { flex: none; color: var(--muted); }

.nav-head {
    display: flex;
    align-items: center;
    gap: 0.5rem;
    padding: 1rem 0.75rem 0.75rem 1rem;
    min-height: 3.75rem;
}

.nav-brand { display: flex; align-items: center; gap: 0.6rem; min-width: 0; flex: 1; }

.nav-brand-mark {
    flex: none;
    display: grid;
    place-items: center;
    width: 1.75rem;
    height: 1.75rem;
    border-radius: 7px;
    background: var(--ink);
    color: var(--surface);
    font-weight: 700;
    font-size: 0.85rem;
}

.nav-brand-name {
    font-size: 1.05rem;
    font-weight: 650;
    letter-spacing: -0.015em;
    white-space: nowrap;
    overflow: hidden;
    text-overflow: ellipsis;
}

.nav-icon-btn {
    flex: none;
    display: grid;
    place-items: center;
    width: 2rem;
    height: 2rem;
    border-radius: 6px;
}
.nav-icon-btn:hover { background: var(--sidebar-hover); }
.nav-icon-btn:hover .nav-icon { color: var(--ink); }

.nav-body {
    flex: 1;
    min-height: 0;
    overflow-y: auto;
    display: flex;
    flex-direction: column;
    gap: 1rem;
    padding: 0.25rem 0.75rem 1rem;
}

.nav-hint { margin: 0; padding: 0 0.6rem; font-size: 0.8rem; color: var(--muted); }

.nav-list { list-style: none; margin: 0; padding: 0; display: flex; flex-direction: column; gap: 2px; }
.nav-list a {
    display: flex;
    align-items: center;
    gap: 0.7rem;
    padding: 0.45rem 0.6rem;
    border-radius: 7px;
    color: var(--ink);
    text-decoration: none;
    white-space: nowrap;
}
.nav-list a:hover { background: var(--sidebar-hover); }
.nav-list a.active { background: var(--sidebar-active); font-weight: 600; }
.nav-list a.active .nav-icon { color: var(--ink); }
.nav-label { overflow: hidden; text-overflow: ellipsis; }

.nav-group { display: flex; flex-direction: column; gap: 2px; }
.nav .nav-group-title {
    display: flex;
    align-items: center;
    justify-content: space-between;
    width: 100%;
    padding: 0.35rem 0.6rem;
    border-radius: 7px;
    font-size: 0.75rem;
    font-weight: 600;
    color: var(--muted);
    text-transform: uppercase;
    letter-spacing: 0.05em;
}
.nav .nav-group-title:hover { background: var(--sidebar-hover); color: var(--ink); }
.nav-group-title .nav-icon { width: 14px; height: 14px; transition: transform 0.15s ease; }
.nav-group.is-folded .nav-group-title .nav-icon { transform: rotate(-90deg); }

/* ---- tenant switcher (platform admin) ----
   Looks like the workspace picker it stands in for: a bordered box on top of
   the nav, with the list dropping down under it. */

.tenant-picker {
    position: relative;
    display: flex;
    align-items: center;
    gap: 0.5rem;
    padding: 0 0.6rem;
    background: var(--surface);
    border: 1px solid var(--rule);
    border-radius: 8px;
    box-shadow: 0 1px 2px rgb(0 0 0 / 0.04);
}
.tenant-picker:hover { border-color: #c3c9d4; }
.tenant-picker:focus-within { border-color: var(--accent); box-shadow: 0 0 0 3px var(--accent-soft); }

.tenant-picker .nav-icon { width: 16px; height: 16px; }

.tenant-picker-input {
    flex: 1;
    min-width: 0;
    padding: 0.5rem 0;
    font: inherit;
    font-weight: 500;
    color: var(--ink);
    background: none;
    border: 0;
    outline: none;
    cursor: pointer;
    text-overflow: ellipsis;
}
.tenant-picker-input::placeholder { color: var(--muted); font-weight: 400; }
.tenant-picker.is-open .tenant-picker-input { cursor: text; }

.tenant-picker-list {
    position: absolute;
    top: calc(100% + 0.3rem);
    left: 0;
    right: 0;
    z-index: 30;
    max-height: min(22rem, 60vh);
    overflow-y: auto;
    margin: 0;
    padding: 0.3rem;
    list-style: none;
    background: var(--surface);
    border: 1px solid var(--rule);
    border-radius: 8px;
    box-shadow: 0 10px 28px rgb(0 0 0 / 0.12);
}

.tenant-picker-option {
    display: flex;
    align-items: center;
    gap: 0.6rem;
    padding: 0.4rem 0.5rem;
    border-radius: 6px;
    cursor: pointer;
}
.tenant-picker-option.is-active { background: var(--sidebar-hover); }
.tenant-picker-option[aria-selected="true"] { font-weight: 600; }
.tenant-picker-option .nav-icon { margin-left: auto; color: var(--accent); }
.tenant-picker-name { overflow: hidden; text-overflow: ellipsis; white-space: nowrap; }
.tenant-picker-empty { padding: 0.5rem; font-size: 0.82rem; color: var(--muted); }

.tenant-mark {
    flex: none;
    display: grid;
    place-items: center;
    width: 1.4rem;
    height: 1.4rem;
    border-radius: 5px;
    background: var(--accent-soft);
    color: var(--accent);
    font-size: 0.72rem;
    font-weight: 700;
}

/* ---- account card ---- */

.nav-foot { padding: 0.6rem 0.75rem 0.75rem; border-top: 1px solid var(--rule); }

.nav-user { position: relative; }

.nav-user-toggle {
    display: flex;
    align-items: center;
    gap: 0.65rem;
    width: 100%;
    padding: 0.45rem 0.5rem;
    border-radius: 8px;
    text-align: left;
}
.nav-user-toggle:hover,
.nav-user-toggle[aria-expanded="true"] { background: var(--sidebar-hover); }

.nav-avatar {
    flex: none;
    display: grid;
    place-items: center;
    width: 2rem;
    height: 2rem;
    border-radius: 8px;
    background: var(--surface);
    border: 1px solid var(--rule);
    font-weight: 600;
    font-size: 0.85rem;
}

.nav-user-text { display: flex; flex-direction: column; min-width: 0; flex: 1; line-height: 1.3; }
.nav-user-name { font-weight: 600; overflow: hidden; text-overflow: ellipsis; white-space: nowrap; }
.nav-user-sub { font-size: 0.75rem; color: var(--muted); overflow: hidden; text-overflow: ellipsis; white-space: nowrap; }
.nav-user-caret { margin-left: auto; display: flex; }
.nav-user-caret .nav-icon { width: 16px; height: 16px; }

/* Opens upward — see the markup. */
.nav-user-menu {
    position: absolute;
    bottom: calc(100% + 0.35rem);
    left: 0;
    right: 0;
    margin: 0;
    padding: 0.3rem;
    list-style: none;
    background: var(--surface);
    border: 1px solid var(--rule);
    border-radius: 8px;
    box-shadow: 0 10px 28px rgb(0 0 0 / 0.12);
    z-index: 30;
}
.nav-user-menu li { margin: 0; }

.nav-user-menu a,
.nav-user-menu .nav-user-menu-item {
    display: flex;
    align-items: center;
    gap: 0.6rem;
    width: 100%;
    padding: 0.45rem 0.55rem;
    text-align: left;
    text-decoration: none;
    color: var(--ink);
    border-radius: 6px;
}
.nav-user-menu a:hover,
.nav-user-menu .nav-user-menu-item:hover { background: var(--sidebar-hover); }

/* Sign out is a form POST, not a link, so its <form> wrapper must not become
   a box of its own. */
.nav-user form { display: contents; }

.nav-signin {
    display: flex;
    align-items: center;
    gap: 0.7rem;
    padding: 0.45rem 0.6rem;
    border-radius: 7px;
    color: var(--ink);
    font-weight: 600;
    text-decoration: none;
}
.nav-signin:hover { background: var(--sidebar-hover); }

/* ---- collapsed rail ----
   Icons only. Every link carries a title, which is its tooltip here. */

.nav--collapsed .nav-head { flex-direction: column; padding: 0.85rem 0.5rem 0.5rem; }
.nav--collapsed .nav-brand { flex: none; justify-content: center; }
.nav--collapsed .nav-brand:empty { display: none; }
.nav--collapsed :is(.nav-brand-name, .nav-label, .nav-hint, .nav-group-title, .nav-user-text, .nav-user-caret) { display: none; }
.nav--collapsed .nav-body { padding-inline: 0.5rem; align-items: center; }
.nav--collapsed .nav-list a,
.nav--collapsed .nav-signin { justify-content: center; padding: 0.55rem; }
.nav--collapsed .nav-group { padding-top: 0.5rem; border-top: 1px solid var(--rule); }
.nav--collapsed .nav-foot { padding-inline: 0.5rem; }
.nav--collapsed .nav-user-toggle { justify-content: center; padding: 0.35rem; }
.nav--collapsed .nav-user-menu { right: auto; min-width: 11rem; }

/* ---- content ---- */

.page-head { margin-bottom: 1.5rem; }
.page-head h1 { margin: 0 0 0.25rem; font-size: 1.75rem; letter-spacing: -0.02em; }

.panel {
    background: var(--surface);
    border: 1px solid var(--rule);
    border-radius: 6px;
    padding: 1.25rem 1.5rem;
    margin-bottom: 1.25rem;
}
.panel h2 { margin: 0 0 1rem; font-size: 1.05rem; }

.muted { color: var(--muted); }
.small { font-size: 0.85rem; }

.field-row { display: flex; flex-wrap: wrap; gap: 1rem; margin-bottom: 0.9rem; }
.field-row label { display: flex; flex-direction: column; gap: 0.25rem; font-size: 0.82rem; color: var(--muted); flex: 1 1 12rem; }
.field-row label.wide { flex: 1 1 100%; }
.field-row input, .field-row select, .field-row textarea {
    font: inherit;
    color: var(--ink);
    padding: 0.45rem 0.55rem;
    border: 1px solid var(--rule);
    border-radius: 4px;
    background: var(--surface);
}

.field-row textarea { resize: vertical; }

/* Blazor's own classes, from EditContext.FieldCssClass — added to InputText/etc.
   once a field has been touched, and to ValidationMessage's own element. */
.field-row input.invalid, .field-row select.invalid, .field-row textarea.invalid {
    border-color: var(--danger);
}
.validation-message {
    color: var(--danger);
    font-size: 0.78rem;
    margin-top: -0.5rem;
}

/* Where a tenant is reached: its slug, its own domains, its retired slugs. */
.addresses { display: grid; grid-template-columns: auto 1fr; gap: 0.3rem 0.9rem; margin: 0.6rem 0; }
.addresses dt { font-size: 0.78rem; color: var(--muted); text-transform: uppercase; letter-spacing: 0.04em; }
.addresses dd { margin: 0; display: flex; flex-wrap: wrap; gap: 0.35rem; align-items: baseline; }

button {
    font: inherit;
    font-weight: 500;
    padding: 0.45rem 1rem;
    border: 1px solid var(--accent);
    border-radius: 4px;
    background: var(--accent);
    color: #fff;
    cursor: pointer;
}
button:disabled { opacity: 0.5; cursor: not-allowed; }
button.link { background: none; border: none; color: var(--accent); padding: 0; text-decoration: underline; }

table { width: 100%; border-collapse: collapse; font-size: 0.9rem; }
thead th {
    text-align: left;
    font-size: 0.72rem;
    letter-spacing: 0.08em;
    text-transform: uppercase;
    color: var(--muted);
    padding: 0.5rem 0.6rem;
    border-bottom: 1px solid var(--rule);
}
tbody td { padding: 0.55rem 0.6rem; border-bottom: 1px solid var(--rule); }
tbody tr:last-child td { border-bottom: 0; }

.error { color: var(--danger); background: var(--danger-soft); padding: 0.6rem 0.8rem; border-radius: 4px; }
.ok { color: var(--ok); background: var(--ok-soft); padding: 0.6rem 0.8rem; border-radius: 4px; }

.facts { display: grid; grid-template-columns: 6rem 1fr; gap: 0.4rem 1rem; margin: 0; }
.facts dt { color: var(--muted); font-size: 0.85rem; }
.facts dd { margin: 0; }

.chip {
    display: inline-block;
    font-size: 0.78rem;
    padding: 0.12em 0.55em;
    border-radius: 3px;
    border: 1px solid;
    margin: 0 0.3rem 0.3rem 0;
}
.chip.on { color: var(--ok); background: var(--ok-soft); border-color: var(--ok); }
.chip.off { color: var(--muted); background: var(--surface-2); border-color: var(--rule); }

.address-list { list-style: none; margin: 0; padding: 0; display: flex; flex-direction: column; gap: 0.35rem; width: 100%; }
.address-list li { display: flex; align-items: center; gap: 0.6rem; }
.address-list button.link { margin-left: auto; }

.feed { list-style: none; margin: 0; padding: 0; display: flex; flex-direction: column; gap: 0.75rem; }
.feed li { border: 1px solid var(--rule); border-radius: 4px; padding: 0.75rem 0.9rem; }
.feed li.unread { border-left: 3px solid var(--accent); }
.feed li p { margin: 0.3rem 0 0; }
.feed-head { display: flex; justify-content: space-between; gap: 1rem; align-items: baseline; }
.feed-head time { font-size: 0.8rem; color: var(--muted); }

/* Only for guard notices rendered outside a host layout; inside one the
   layout already supplies the padding. */
.guard { padding: 2rem clamp(1rem, 4vw, 3rem); max-width: 68rem; }

@media (max-width: 48rem) {
    .app { flex-direction: column; }
    /* On a phone the sidebar stacks above the page instead of pinning
       beside it, and the rail toggle has nothing to save room from. */
    .sidebar,
    .sidebar:has(> .nav--collapsed) { position: static; width: 100%; height: auto; flex: none; border-right: 0; border-bottom: 1px solid var(--rule); }
    .nav-collapse-toggle { display: none; }
}

/* ---- authentication -------------------------------------------------------
   The login, sign-out and forbidden pages render OUTSIDE the Blazor Router as
   standalone documents, so they get no .app / .content shell and have to supply
   their own centring. */

.auth {
    min-height: 100vh;
    display: flex;
    align-items: center;
    justify-content: center;
    padding: 2rem 1rem;
}

.auth-card {
    background: var(--surface);
    border: 1px solid var(--rule);
    border-radius: 6px;
    padding: 1.75rem;
    width: 100%;
    max-width: 22rem;
    display: flex;
    flex-direction: column;
    gap: 0.9rem;
}

.auth-card h1 { margin: 0; font-size: 1.35rem; letter-spacing: -0.02em; }
.auth-card p { margin: 0; font-size: 0.9rem; }

.auth-card label {
    display: flex;
    flex-direction: column;
    gap: 0.25rem;
    font-size: 0.82rem;
    color: var(--muted);
}

.auth-card input {
    font: inherit;
    color: var(--ink);
    padding: 0.45rem 0.6rem;
    border: 1px solid var(--rule);
    border-radius: 4px;
    background: var(--surface);
}

/* The vendor door, visibly distinct from a tenant's — a platform sign-in page
   that looks identical to a customer's is one an operator can mistake for it. */
.auth-card--platform { border-top: 3px solid var(--accent); }

.auth-error {
    color: var(--danger);
    background: var(--danger-soft);
    padding: 0.6rem 0.8rem;
    border-radius: 4px;
    font-size: 0.85rem;
}

.badge {
    font-size: 0.7rem;
    text-transform: uppercase;
    letter-spacing: 0.04em;
    padding: 0.1rem 0.4rem;
    border-radius: 3px;
    color: var(--accent);
    background: var(--accent-soft);
}

/* A link that should read as the primary action of a panel. */
.primary-link {
    display: inline-block;
    font-weight: 500;
    padding: 0.45rem 1rem;
    border: 1px solid var(--accent);
    border-radius: 4px;
    background: var(--accent);
    color: #fff;
    text-decoration: none;
}

/* ---- role editor ----------------------------------------------------------
   Rendered from the server's permission catalogue, so the grouping is by
   whatever modules the host composes rather than anything hard-coded here. */

.chips { display: flex; flex-wrap: wrap; gap: 0.35rem; margin: 0.5rem 0; }

.perm-group {
    border: 1px solid var(--rule);
    border-radius: 4px;
    padding: 0.6rem 0.9rem 0.9rem;
    margin: 0.75rem 0;
}

.perm-group legend {
    font-size: 0.75rem;
    text-transform: uppercase;
    letter-spacing: 0.05em;
    color: var(--muted);
    padding: 0 0.35rem;
}

.perm {
    display: flex;
    align-items: baseline;
    gap: 0.5rem;
    padding: 0.2rem 0;
    font-size: 0.9rem;
}

.perm code { font-size: 0.78rem; margin-left: 0.4rem; }

/* ---- settings editor ------------------------------------------------------
   Rendered from the server's descriptor catalogue, so the grouping and the
   control types come from whatever modules the host composes. */

.setting {
    padding: 0.7rem 0;
    border-bottom: 1px solid var(--rule);
    display: flex;
    flex-direction: column;
    gap: 0.25rem;
}

.setting:last-child { border-bottom: 0; }

.setting label { display: flex; flex-direction: column; gap: 0.3rem; }

.setting-name { font-weight: 500; color: var(--ink); font-size: 0.92rem; }

.setting input, .setting select {
    font: inherit;
    color: var(--ink);
    padding: 0.4rem 0.6rem;
    border: 1px solid var(--rule);
    border-radius: 4px;
    background: var(--surface);
    max-width: 28rem;
}
