/* login.html-only styles, extracted from an inline <style> block
   (2026-08-15) so the dashboard CSP's style-src can drop 'unsafe-inline'
   without needing a content hash that would silently break on any future
   edit. Kept separate from dashboard.css (rather than merged into it)
   because dashboard.css is also loaded by index.html - a body-level
   flex/centering rule here would break the real dashboard's own sidebar
   layout if it lived in the shared file. Also shared, unmodified, by
   reset-password.html (added 2026-09-02, self-service password reset) -
   the same standalone-auth-page shell, so its own new elements reuse
   these classes rather than duplicating them. */
body {
  min-height: 100vh;
  display: flex;
  align-items: center;
  justify-content: center;
}
.login-card {
  width: 360px;
  max-width: 100%;
  background: var(--card);
  border: 1px solid var(--line);
  border-radius: var(--radius);
  padding: 32px 28px;
}
.login-brand {
  display: flex;
  align-items: center;
  gap: 8px;
  font-weight: 700;
  font-size: 15px;
  margin-bottom: 24px;
}
.login-error {
  color: var(--danger);
  font-size: 12.5px;
  margin: 0 0 12px;
  display: none;
}
/* reset-password.html only - mirrors .login-error's own shape/toggle
   convention (JS sets .style.display, never relies on [hidden]) for the
   opposite (success) case. */
.login-success {
  color: #1a7f37;
  font-size: 12.5px;
  margin: 0 0 12px;
  display: none;
}
/* reset-password.html only - a small centered secondary link below the
   main form/message (e.g. "Request a new link", "Back to login"). */
.login-link-row {
  text-align: center;
  font-size: 12.5px;
  color: var(--ink-faint);
  margin: 16px 0 0;
}
.login-link-row a { color: var(--accent); text-decoration: none; }
.login-link-row a:hover { text-decoration: underline; }
#loginSubmitBtn,
#twoFactorSubmitBtn,
#rpRequestBtn,
#rpResetBtn,
#rpGoToLoginBtn { width: 100%; margin-top: 4px; }

/* shopify-welcome.html only (added 2026-09-10) - the post-install
   Terms/Privacy click-through gate. Reuses .login-card/.login-brand/
   .login-error from the shared shell above; these three are new. */
.welcome-heading {
  font-size: 20px;
  font-weight: 700;
  margin: 0 0 8px;
}
.welcome-text {
  font-size: 13px;
  color: var(--ink-soft);
  line-height: 1.5;
  margin: 0 0 16px;
}
.welcome-policy-links {
  text-align: center;
  font-size: 12.5px;
  margin: 0 0 20px;
}
.welcome-policy-links a { color: var(--accent); text-decoration: none; }
.welcome-policy-links a:hover { text-decoration: underline; }
#acceptTermsBtn { width: 100%; }

/* login.html's two-factor step (added 2026-09-28) - a checkbox beside its
   text, not stacked above it like the text fields. */
.login-checkbox-row {
  display: flex !important;
  flex-direction: row !important;
  align-items: center;
  gap: 8px;
  font-size: 13px;
  color: var(--ink-soft);
  margin: 4px 0 14px;
  cursor: pointer;
}
.login-checkbox-row input { width: auto; margin: 0; }
