/* =========================================================================
   SIDES LABS — base
   Reset, self-hosted typography, layout primitives, focus, gate states.
   No literal colour here: every colour comes from tokens.css.
   ========================================================================= */

/* ---- Self-hosted Inter (DESIGN_TOKENS.md §6) ---------------------------- *
 * Subset to latin + latin-ext + the punctuation and arrows the UI uses, so
 * German copy is correct without shipping the full face. Licence and the
 * subsetting range: assets/fonts/OFL.txt and frontend/README.md.
 * ------------------------------------------------------------------------ */

@font-face {
  font-family: 'Inter';
  font-style: normal;
  font-weight: 400;
  font-display: swap;
  src: url('../fonts/inter-400.woff2') format('woff2');
}

@font-face {
  font-family: 'Inter';
  font-style: normal;
  font-weight: 600;
  font-display: swap;
  src: url('../fonts/inter-600.woff2') format('woff2');
}

@font-face {
  font-family: 'Inter';
  font-style: normal;
  font-weight: 700;
  font-display: swap;
  src: url('../fonts/inter-700.woff2') format('woff2');
}

/* ---- Reset -------------------------------------------------------------- */

*,
*::before,
*::after {
  box-sizing: border-box;
}

html {
  scroll-behavior: smooth;
  /* 200 % zoom and 320 px width are requirements, not nice-to-haves. */
  -webkit-text-size-adjust: 100%;
}

body {
  margin: 0;
  font-family: var(--font);
  font-size: 15px;
  line-height: 1.6;
  color: var(--doc-ink);
  background: var(--doc-bg);
  -webkit-font-smoothing: antialiased;
  /* The page body never scrolls horizontally; wide content scrolls in its
     own container (see .scroll-x). */
  overflow-x: hidden;
}

img,
svg,
video {
  max-width: 100%;
}

img {
  height: auto;
}

/* ---- Typography --------------------------------------------------------- */

h1,
h2,
h3,
h4 {
  letter-spacing: -.02em;
  line-height: 1.14;
  margin: 0 0 .4em;
}

h1 { font-size: clamp(28px, 5vw, 44px); font-weight: 700; }
h2 { font-size: clamp(22px, 3vw, 30px); font-weight: 700; }
h3 { font-size: 18px; font-weight: 600; }
h4 { font-size: 15px; font-weight: 600; }

p {
  margin: 0 0 16px;
  max-width: 68ch;
}

a {
  color: var(--sd-secondary);
  text-decoration: none;
}

a:hover {
  text-decoration: underline;
}

code,
kbd,
samp,
pre {
  font-family: var(--mono);
  font-size: .88em;
}

hr {
  border: 0;
  border-top: 1px solid var(--doc-line);
  margin: 32px 0;
}

.eyebrow {
  font-size: 12px;
  font-weight: 700;
  letter-spacing: .12em;
  text-transform: uppercase;
  color: var(--sd-secondary);
  margin-bottom: 12px;
}

.lede {
  font-size: clamp(16px, 2vw, 19px);
  color: var(--doc-ink-soft);
  max-width: 62ch;
}

.text-soft {
  color: var(--doc-ink-soft);
}

/* ---- Focus: always visible (DESIGN_TOKENS.md §8.2) ---------------------- *
 * `outline: none` without a replacement is an audit finding. Nothing in this
 * codebase removes an outline; components add a ring on top of it.
 * ------------------------------------------------------------------------ */

:focus-visible {
  outline: 3px solid var(--sd-secondary);
  outline-offset: 2px;
  border-radius: var(--radius);
}

/* On the always-dark brand surfaces the teal ring disappears — use the
   theme-invariant ink instead. */
.on-brand :focus-visible {
  outline-color: var(--brand-on-dark);
}

/* Skip link — the first tab stop on every page that carries site chrome.
   {en,de}/login.html has none: it is a single focused card with nothing to skip. */
.skip-link {
  position: absolute;
  left: 8px;
  top: -80px;
  z-index: 100;
  padding: 10px 16px;
  border-radius: var(--radius);
  background: var(--doc-panel);
  color: var(--doc-ink);
  border: 1px solid var(--doc-line);
  box-shadow: var(--shadow-pop);
  font-weight: 600;
  transition: top .12s;
}

.skip-link:focus {
  top: 8px;
  text-decoration: none;
}

/* ---- Layout primitives -------------------------------------------------- */

.container {
  width: 100%;
  max-width: 1160px;
  margin: 0 auto;
  padding: 0 clamp(16px, 5vw, 40px);
}

.section {
  padding: clamp(40px, 8vw, 88px) 0;
}

.section-head {
  margin-bottom: 40px;
}

.stack-8 > * + * { margin-top: 8px; }
.stack-16 > * + * { margin-top: 16px; }
.stack-24 > * + * { margin-top: 24px; }

.grid-auto {
  display: grid;
  grid-template-columns: repeat(auto-fit, minmax(260px, 1fr));
  gap: 20px;
}

/* Wide content scrolls inside its own container (DESIGN_TOKENS.md §8.5). */
.scroll-x {
  overflow-x: auto;
  -webkit-overflow-scrolling: touch;
}

/* A component that sets `display` on a class defeats the `hidden` attribute:
   `[hidden]` and `.thing` have equal specificity, so whichever stylesheet
   loads last wins, and that is the component. A class that sets `display` on an
   element that is ever hidden via the `hidden` ATTRIBUTE must pair itself with
   `[hidden]`; the many classes that set `display` and are never hidden that way
   need nothing.

   **No list of them lives here.** It said "the two that qualify" and named two;
   `U-796` made it three and counted: ten sheets already pair themselves, twenty
   rules in all. A number in prose that nothing reads is wrong the day after it is
   written, and this one had been — worse, it reads as the complete set, so the
   next author concludes their own sheet is not concerned. Ask the tree instead:
   `grep -rn '\[hidden\]' assets/css`. (It will also show what is MISSING only by
   its absence: `.app-checklist` in `pages/apps.css` sets `display` and is hidden
   by the attribute in `app-publication.js`, and pairs itself nowhere.) */
[hidden] {
  display: none;
}

.visually-hidden {
  position: absolute;
  width: 1px;
  height: 1px;
  margin: -1px;
  padding: 0;
  overflow: hidden;
  clip: rect(0 0 0 0);
  white-space: nowrap;
  border: 0;
}

/* ---- The auth gate ------------------------------------------------------ *
 * assets/js/gate.js sets `data-gate="pending"` on <html> synchronously in
 * <head>, before the first paint. Gated content is therefore never painted
 * for a visitor who turns out not to be signed in (L-FE-02), and the page
 * shows a neutral resolving shell instead.
 *
 * There are exactly two values: `pending` and `ready`. A `denied` value was
 * tried and removed (L-FE-07) — a principal who is signed in but lacks a scope
 * keeps the shell and gets a 403 in the view, because hiding the page turns a
 * permission problem into a blank screen.
 *
 * Without JavaScript the gate never resolves — that is correct: the portal
 * requires JavaScript, and every gated page carries a <noscript> that says so.
 * ------------------------------------------------------------------------ */

[data-gate="pending"] .gated {
  display: none;
}

[data-gate="ready"] .gate-pending-only {
  display: none;
}

/* Where the resolving message, and then the sign-in panel, are shown. */
.gate-pending-only {
  display: flex;
  flex-direction: column;
  align-items: center;
  justify-content: center;
  min-height: 60vh;
  padding: 32px 0;
}

/* ---- Motion (DESIGN_TOKENS.md §8.3) ------------------------------------- */

@media (prefers-reduced-motion: reduce) {
  html {
    scroll-behavior: auto;
  }

  *,
  *::before,
  *::after {
    animation-duration: .001ms;
    animation-iteration-count: 1;
    transition-duration: .001ms;
  }
}
