/* auth/auth.css — Phase 13b styles. The sidebar #auth-mount renders
   either the GIS sign-in button (signed out) or a small avatar tile
   with sign-out (signed in). Empty when AUTH_ENABLED=false. */

#auth-mount {
  display: flex;
  justify-content: center;
  margin: 0 0 8px 0;
  min-height: 0;
}

#auth-mount:empty { margin: 0; }

/* GIS button container — Google's iframe sets its own internal sizing,
   we just give it a centered slot. */
.auth-signin-slot {
  display: flex;
  justify-content: center;
  width: 100%;
}

/* Signed-in tile — avatar (32px circle), name, sign-out button.
   Phase 13f-i tweak — dropped the wrapper background + border per
   Maurice; the tile now flows flush with the sidebar chrome. Padding
   trimmed to inherit the sidebar's natural alignment. */
.auth-tile {
  display: flex;
  align-items: center;
  gap: 8px;
  width: 100%;
}

.auth-avatar-btn {
  position: relative;
  width: 32px;
  height: 32px;
  flex: 0 0 32px;
  padding: 0;
  border: none;
  border-radius: 50%;
  background: #dde1ea;
  cursor: pointer;
  overflow: hidden;
  display: flex;
  align-items: center;
  justify-content: center;
  font-family: 'Inter', sans-serif;
  font-size: 14px;
  font-weight: 600;
  color: #1a1d26;
}
.auth-avatar-btn:hover { background: #c8cee0; }

.auth-avatar-img {
  width: 100%;
  height: 100%;
  object-fit: cover;
  border-radius: 50%;
}

.auth-avatar-initial {
  line-height: 1;
}

/* Admin role badge — small star in the top-right of the avatar. */
.auth-role-badge {
  position: absolute;
  bottom: -2px;
  right: -2px;
  width: 14px;
  height: 14px;
  background: #f0b400;
  color: #1a1d26;
  border: 1.5px solid #fff;
  border-radius: 50%;
  font-size: 9px;
  line-height: 11px;
  text-align: center;
  font-weight: 700;
}

.auth-meta {
  flex: 1;
  min-width: 0;
  display: flex;
  flex-direction: column;
  gap: 2px;
}

/* Phase 13f-i — name + role pill on one row. Auth tile is narrow,
   so the name truncates with ellipsis if needed and the pill stays
   at its natural size on the right. */
.auth-name-row {
  display: flex;
  align-items: center;
  gap: 6px;
  min-width: 0;
}

.auth-name {
  font-family: 'Inter', sans-serif;
  font-size: 12px;
  font-weight: 500;
  color: #1a1d26;
  white-space: nowrap;
  overflow: hidden;
  text-overflow: ellipsis;
  flex: 1;
  min-width: 0;
}

/* Phase 13f-i — role pill mirrors .auth-status-role from
   admin-top.css (settings page) so the same admin / reader chip
   reads identically across the reader sidebar + the settings
   header. */
.auth-role-pill {
  display: inline-flex;
  align-items: center;
  justify-content: center;
  font-family: 'Inter', sans-serif;
  font-size: 10px;
  font-weight: 600;
  letter-spacing: 0.04em;
  text-transform: uppercase;
  padding: 0 8px;
  height: 18px;
  border-radius: 9px;
  border: 1px solid;
  line-height: 1;
  flex-shrink: 0;
}
.auth-role-pill-admin  { color: #1d3fa8; border-color: #bccfee; background: #eef3fc }
.auth-role-pill-reader { color: #5a6172; border-color: #dde1ea; background: #f3f4f8 }

.auth-signout-btn {
  align-self: flex-start;
  background: transparent;
  border: none;
  padding: 0;
  font-family: 'Inter', sans-serif;
  font-size: 11px;
  color: #5a6175;
  cursor: pointer;
  text-decoration: underline;
  text-underline-offset: 2px;
}
.auth-signout-btn:hover { color: #1a1d26; }

/* Error fallback — visible if /api/auth/google rejects or GIS fails to load. */
.auth-error {
  font-family: 'Inter', sans-serif;
  font-size: 11px;
  color: #b3261e;
  background: #fff4f4;
  border: 1px solid #f3d6d6;
  border-radius: 6px;
  padding: 4px 8px;
  width: 100%;
  text-align: center;
}
