:root {
  --font-sans: -apple-system, BlinkMacSystemFont, "Segoe UI", Roboto, Helvetica, Arial, sans-serif;
  --font-heading: Georgia, "Iowan Old Style", "Palatino Linotype", "Book Antiqua", serif;

  --auth-bg: var(--theme-bg);
  --auth-card-bg: var(--theme-surface);
  --auth-border: var(--theme-border);
  --auth-text: var(--theme-text);
  --auth-muted: var(--theme-muted);
  --auth-radius: 16px;

  /* Teal actions and midnight-blue text match the public homepage. */
  --auth-accent: var(--theme-accent);
  --auth-accent-text: var(--theme-accent-text);

  --auth-error: #b42318;
  --auth-error-bg: #fdecea;

  /* Role tint — used only for the small chip under the school name, nothing else. */
  --auth-role-admin: var(--theme-primary);
  --auth-role-staff: #1e6296;
  --auth-role-parent: #12665c;
  --role-color: var(--auth-role-admin);
  --role-chip-bg: #e4edf7;
}

.auth-role-admin  { --role-color: var(--auth-role-admin);  --role-chip-bg: #e4edf7; }
.auth-role-staff  { --role-color: var(--auth-role-staff);  --role-chip-bg: #e6f1fc; }
.auth-role-parent { --role-color: var(--auth-role-parent); --role-chip-bg: #dff6f1; }

* { box-sizing: border-box; }

body.auth-body {
  margin: 0;
  min-height: 100vh;
  display: flex;
  align-items: center;
  justify-content: center;
  padding: 24px;
  font-family: var(--font-sans);
  background: var(--auth-bg);
  color: var(--auth-text);
}

.auth-shell {
  width: 100%;
  max-width: 860px;
  display: flex;
  border-radius: var(--auth-radius);
  overflow: hidden;
  box-shadow: 0 1px 3px rgba(16, 42, 67, 0.06);
}

.auth-photo {
  flex: 1 1 45%;
  min-height: 420px;
  background-size: cover;
  background-position: top center;
}

.auth-card {
  flex: 1 1 400px;
  width: 100%;
  max-width: 400px;
  background: var(--auth-card-bg);
  border: 1px solid var(--auth-border);
  padding: 36px 32px 32px;
}

@media (min-width: 701px) {
  .auth-card { border-radius: 0 var(--auth-radius) var(--auth-radius) 0; border-left: none; }
}

@media (max-width: 700px) {
  .auth-shell { flex-direction: column; max-width: 400px; }
  .auth-photo { min-height: 160px; border-radius: var(--auth-radius) var(--auth-radius) 0 0; }
  .auth-card { max-width: 100%; border-radius: 0 0 var(--auth-radius) var(--auth-radius); }
}

.auth-logo {
  display: block;
  max-width: 110px;
  width: 100%;
  height: auto;
  border-radius: 50%;
  object-fit: cover;
  margin: 0 auto 14px;
}

.auth-brand { text-align: center; margin-bottom: 26px; }
.auth-brand h1 {
  font-family: var(--font-heading);
  font-size: 1.3rem;
  margin: 0 0 10px;
  font-weight: 700;
  color: var(--auth-text);
}

/* unauthorized.php reuses .auth-brand with a plain <p> subtitle, not the chip below. */
.auth-brand p { margin: 0; color: var(--auth-muted); font-size: 0.8rem; }

.auth-role-chip {
  display: inline-block;
  padding: 4px 14px;
  border-radius: 999px;
  font-size: 0.72rem;
  font-weight: 600;
  color: var(--role-color);
  background: var(--role-chip-bg);
}

.auth-alert {
  background: var(--auth-error-bg);
  color: var(--auth-error);
  border-radius: 10px;
  padding: 12px 14px;
  font-size: 0.875rem;
  margin-bottom: 20px;
}

.auth-alert-success { background: #e3f7f3; color: #0b6b5c; }

.auth-field { margin-bottom: 16px; }

.auth-form label {
  display: block;
  font-size: 0.8rem;
  font-weight: 600;
  margin-bottom: 6px;
  color: var(--auth-muted);
}

.auth-form input,
.auth-form select,
.auth-form textarea {
  width: 100%;
  min-height: 48px;
  padding: 12px 14px;
  border: 1px solid var(--auth-border);
  border-radius: 10px;
  font-size: 1rem;
  font-family: inherit;
  background: var(--theme-bg);
  color: var(--auth-text);
  transition: border-color 0.15s, box-shadow 0.15s;
}

.auth-form textarea { min-height: 96px; resize: vertical; }

.auth-form input:focus,
.auth-form select:focus,
.auth-form textarea:focus {
  outline: none;
  border-color: var(--theme-focus);
  box-shadow: 0 0 0 3px rgba(8, 126, 139, 0.2);
  background: #fff;
}

/* Error state: a single red, only on the message above and the two fields it applies to.
   attempt_login() returns one generic message that never says which field was wrong (by
   design — it must not reveal whether a username exists), so both fields take the state
   together rather than guessing which one to blame. */
.auth-form input.has-error { border-color: var(--auth-error); background: #fff8f7; }
.auth-form input.has-error:focus { box-shadow: 0 0 0 3px rgba(180, 35, 24, 0.15); }

.auth-submit,
a.auth-submit {
  display: block;
  width: 100%;
  min-height: 48px;
  margin-top: 22px;
  padding: 13px;
  border: none;
  border-radius: 10px;
  background: var(--auth-accent);
  color: var(--auth-accent-text);
  font-size: 1rem;
  font-weight: 700;
  text-align: center;
  text-decoration: none;
  cursor: pointer;
  transition: filter 0.15s, transform 0.05s;
}

.auth-submit:hover,
a.auth-submit:hover { filter: brightness(1.06); }
.auth-submit:active,
a.auth-submit:active { transform: translateY(1px); }

@media (max-width: 420px) {
  .auth-card { padding: 30px 22px 26px; border-radius: 14px; }
}

.auth-body a:focus-visible, .auth-body button:focus-visible { outline: 3px solid var(--theme-focus); outline-offset: 4px; }
