/* =========================================================
   MikroTik VRF Manager — Design System
   Pure CSS, no framework. Modern admin dashboard look.
   ========================================================= */

/* ===== DESIGN TOKENS ===== */
:root {
    /* Brand */
    --primary:        #4f46e5;
    --primary-hover:  #4338ca;
    --primary-active: #3730a3;
    --primary-soft:   #eef2ff;
    --primary-border: #c7d2fe;

    /* Cold neutrals (slate) */
    --gray-25:  #fcfcfd;
    --gray-50:  #f8fafc;
    --gray-100: #f1f5f9;
    --gray-200: #e2e8f0;
    --gray-300: #cbd5e1;
    --gray-400: #94a3b8;
    --gray-500: #64748b;
    --gray-600: #475569;
    --gray-700: #334155;
    --gray-800: #1e293b;
    --gray-900: #0f172a;

    /* Semantic */
    --success:        #16a34a;
    --success-strong: #15803d;
    --success-soft:   #f0fdf4;
    --success-border: #bbf7d0;
    --success-text:   #166534;

    --danger:        #dc2626;
    --danger-hover:  #b91c1c;
    --danger-soft:   #fef2f2;
    --danger-border: #fecaca;
    --danger-text:   #991b1b;

    --warning:        #d97706;
    --warning-soft:   #fffbeb;
    --warning-border: #fde68a;
    --warning-text:   #92400e;

    --info-soft:   #eff6ff;
    --info-border: #bfdbfe;
    --info-text:   #1e40af;

    /* Accents (badges) */
    --accent-teal:        #0d9488;
    --accent-teal-soft:   #f0fdfa;
    --accent-teal-border: #99f6e4;
    --accent-violet:        #7c3aed;
    --accent-violet-soft:   #f5f3ff;
    --accent-violet-border: #ddd6fe;

    /* Surfaces */
    --bg:           var(--gray-50);
    --surface:      #ffffff;
    --border:       var(--gray-200);
    --border-strong: var(--gray-300);

    /* Typography */
    --font-sans: "Inter", "SF Pro Text", -apple-system, BlinkMacSystemFont,
                 "Segoe UI", system-ui, Roboto, "Helvetica Neue", Arial, sans-serif;
    --font-mono: ui-monospace, "SF Mono", "Cascadia Code", "JetBrains Mono",
                 Menlo, Consolas, monospace;

    /* Spacing scale */
    --sp-1: 4px;
    --sp-2: 8px;
    --sp-3: 12px;
    --sp-4: 16px;
    --sp-5: 20px;
    --sp-6: 24px;
    --sp-8: 32px;

    /* Radii */
    --radius-sm: 6px;
    --radius:    8px;
    --radius-lg: 12px;
    --radius-full: 999px;

    /* Shadows (very subtle) */
    --shadow-xs: 0 1px 2px rgba(15, 23, 42, 0.05);
    --shadow-sm: 0 1px 3px rgba(15, 23, 42, 0.07), 0 1px 2px rgba(15, 23, 42, 0.04);
    --shadow-md: 0 4px 12px rgba(15, 23, 42, 0.08);

    /* Focus ring */
    --ring: 0 0 0 3px rgba(79, 70, 229, 0.18);

    /* Layout */
    --content-width: 1160px;
}

/* ===== RESET & BASE ===== */
*, *::before, *::after { margin: 0; padding: 0; box-sizing: border-box; }

html { -webkit-text-size-adjust: 100%; }

body {
    font-family: var(--font-sans);
    font-size: 14px;
    line-height: 1.5;
    background: var(--bg);
    color: var(--gray-800);
    -webkit-font-smoothing: antialiased;
    text-rendering: optimizeLegibility;
}

code {
    font-family: var(--font-mono);
    font-size: 0.85em;
    background: var(--gray-100);
    border: 1px solid var(--gray-200);
    border-radius: 4px;
    padding: 1px 5px;
    color: var(--gray-700);
}

h1, h2, h3, h4 { color: var(--gray-900); font-weight: 600; }

a { color: var(--primary); }

/* ===== TOPBAR ===== */
.topbar {
    background: var(--surface);
    border-bottom: 1px solid var(--border);
    position: sticky;
    top: 0;
    z-index: 50;
}
.topbar-inner {
    max-width: var(--content-width);
    margin: 0 auto;
    padding: var(--sp-3) var(--sp-5);
    display: flex;
    align-items: center;
    gap: var(--sp-4);
}
.brand {
    display: flex;
    align-items: center;
    gap: var(--sp-3);
    min-width: 0;
}
.brand-mark {
    width: 32px;
    height: 32px;
    border-radius: var(--radius);
    background: linear-gradient(135deg, var(--primary) 0%, var(--accent-violet) 100%);
    color: #fff;
    font-weight: 700;
    font-size: 15px;
    display: flex;
    align-items: center;
    justify-content: center;
    flex-shrink: 0;
    letter-spacing: -0.5px;
}
.brand-name {
    font-size: 15px;
    font-weight: 600;
    color: var(--gray-900);
    white-space: nowrap;
}
.conn-status {
    display: inline-flex;
    align-items: center;
    gap: var(--sp-2);
    margin-left: var(--sp-2);
    padding: 4px 10px;
    border: 1px solid var(--border);
    border-radius: var(--radius-full);
    background: var(--gray-50);
    font-size: 12px;
    color: var(--gray-600);
    font-family: var(--font-mono);
    white-space: nowrap;
    overflow: hidden;
    text-overflow: ellipsis;
}
.conn-dot {
    width: 7px;
    height: 7px;
    border-radius: 50%;
    background: var(--success);
    flex-shrink: 0;
    box-shadow: 0 0 0 3px rgba(22, 163, 74, 0.15);
}
.topbar-spacer { flex: 1; }
.logout-btn {
    display: inline-flex;
    align-items: center;
    padding: 6px 14px;
    font-size: 13px;
    font-weight: 500;
    color: var(--gray-700);
    background: var(--surface);
    border: 1px solid var(--border);
    border-radius: var(--radius-sm);
    text-decoration: none;
    transition: background 0.15s, border-color 0.15s;
    white-space: nowrap;
}
.logout-btn:hover { background: var(--gray-50); border-color: var(--border-strong); }
.logout-btn:focus-visible { outline: none; box-shadow: var(--ring); }

/* ===== TAB NAVIGATION ===== */
.tabs-bar {
    background: var(--surface);
    border-bottom: 1px solid var(--border);
}
.tabs {
    max-width: var(--content-width);
    margin: 0 auto;
    padding: 0 var(--sp-5);
    display: flex;
    gap: var(--sp-1);
    overflow-x: auto;
}
.tab {
    padding: 12px 14px;
    font-size: 13.5px;
    font-weight: 500;
    color: var(--gray-500);
    cursor: pointer;
    border-bottom: 2px solid transparent;
    margin-bottom: -1px;
    white-space: nowrap;
    user-select: none;
    transition: color 0.15s, border-color 0.15s;
}
.tab:hover { color: var(--gray-800); }
.tab.active {
    color: var(--primary);
    border-bottom-color: var(--primary);
}
.tab-content { display: none; }
.tab-content.active { display: block; }

/* ===== MAIN CONTENT / CONTAINER ===== */
.page-main {
    max-width: var(--content-width);
    margin: 0 auto;
    padding: var(--sp-6) var(--sp-5) 64px;
}
.container {
    background: var(--surface);
    border: 1px solid var(--border);
    border-radius: var(--radius-lg);
    box-shadow: var(--shadow-xs);
    padding: var(--sp-6);
}
.section-title {
    font-size: 18px;
    font-weight: 600;
    letter-spacing: -0.2px;
    margin-bottom: var(--sp-4);
}
.subsection {
    margin-top: var(--sp-8);
    padding-top: var(--sp-5);
    border-top: 1px solid var(--border);
}
.subsection h4 {
    font-size: 14px;
    font-weight: 600;
    margin-bottom: var(--sp-3);
}
.subsection-header {
    display: flex;
    align-items: center;
    justify-content: space-between;
    gap: var(--sp-3);
    flex-wrap: wrap;
}
.subsection-header h4 {
    margin-bottom: 0;
}
.btn-sync {
    background: var(--gray-50);
    color: var(--gray-800);
    border: 1px solid var(--border);
    border-radius: var(--radius);
    padding: var(--sp-2) var(--sp-4);
    font-size: 13px;
    font-weight: 600;
    cursor: pointer;
    transition: background 0.15s ease, border-color 0.15s ease;
}
.btn-sync:hover {
    background: var(--gray-100, #eef0f3);
    border-color: var(--primary-border);
}
.btn-sync:active {
    transform: translateY(1px);
}

/* ===== INFO BOX ===== */
.info-box {
    background: var(--gray-50);
    border: 1px solid var(--border);
    border-left: 3px solid var(--primary-border);
    border-radius: var(--radius);
    padding: var(--sp-4);
    margin: var(--sp-4) 0;
    font-size: 13px;
    color: var(--gray-600);
}
.info-box h4 {
    font-size: 13px;
    font-weight: 600;
    color: var(--gray-800);
    margin-bottom: var(--sp-2);
}
.info-box p { margin: var(--sp-1) 0; }
.info-box strong { color: var(--gray-800); }
.info-box.info-box-success {
    background: var(--success-soft);
    border-color: var(--success-border);
    border-left-color: var(--success);
}
.info-box.info-box-success h4 { color: var(--success-text); }

/* ===== FLASH MESSAGES ===== */
.message {
    display: flex;
    align-items: flex-start;
    gap: var(--sp-3);
    padding: var(--sp-3) var(--sp-4);
    margin: var(--sp-4) 0;
    border-radius: var(--radius);
    border: 1px solid;
    font-size: 13.5px;
}
.message b { font-weight: 500; }
.message::before {
    font-weight: 700;
    font-size: 13px;
    width: 18px;
    height: 18px;
    border-radius: 50%;
    display: inline-flex;
    align-items: center;
    justify-content: center;
    flex-shrink: 0;
    margin-top: 1px;
}
.message.success {
    background: var(--success-soft);
    border-color: var(--success-border);
    color: var(--success-text);
}
.message.success::before { content: "\2713"; background: var(--success); color: #fff; }
.message.error {
    background: var(--danger-soft);
    border-color: var(--danger-border);
    color: var(--danger-text);
}
.message.error::before { content: "\2715"; background: var(--danger); color: #fff; font-size: 10px; }
.message.info {
    background: var(--info-soft);
    border-color: var(--info-border);
    color: var(--info-text);
}
.message.info::before { content: "i"; background: var(--info-text); color: #fff; font-style: italic; }

/* Empty / warning notices */
.empty-state {
    padding: var(--sp-5);
    border: 1px dashed var(--border-strong);
    border-radius: var(--radius);
    background: var(--gray-25);
    color: var(--gray-500);
    font-size: 13.5px;
    text-align: center;
}
.empty-state.warning {
    background: var(--warning-soft);
    border: 1px solid var(--warning-border);
    color: var(--warning-text);
    text-align: left;
}

/* ===== FORMS ===== */
.form-group { margin: var(--sp-5) 0; }
label {
    display: block;
    font-weight: 500;
    font-size: 13px;
    color: var(--gray-700);
    margin-bottom: var(--sp-2);
}
input[type="text"],
input[type="password"],
input[type="number"],
select {
    width: 100%;
    padding: 8px 12px;
    font-size: 14px;
    font-family: inherit;
    color: var(--gray-900);
    background: var(--surface);
    border: 1px solid var(--border-strong);
    border-radius: var(--radius-sm);
    transition: border-color 0.15s, box-shadow 0.15s;
}
input::placeholder { color: var(--gray-400); }
input[type="text"]:focus,
input[type="password"]:focus,
input[type="number"]:focus,
select:focus {
    outline: none;
    border-color: var(--primary);
    box-shadow: var(--ring);
}
input[type="checkbox"],
input[type="radio"] {
    width: 15px;
    height: 15px;
    accent-color: var(--primary);
    cursor: pointer;
    flex-shrink: 0;
}
.field-hint {
    display: block;
    margin-top: var(--sp-2);
    font-size: 12.5px;
    color: var(--gray-500);
}
.field-hint strong { color: var(--gray-700); }
.field-error {
    margin-top: var(--sp-2);
    font-size: 13px;
    color: var(--danger);
}
.input-mono {
    font-family: var(--font-mono);
    font-size: 13px;
}
.form-narrow { max-width: 420px; }

/* Radio group */
.radio-group {
    display: flex;
    flex-wrap: wrap;
    gap: var(--sp-3) var(--sp-6);
    margin-top: var(--sp-2);
}
.radio-label {
    display: inline-flex;
    align-items: center;
    gap: var(--sp-2);
    font-weight: 400;
    font-size: 13.5px;
    color: var(--gray-700);
    cursor: pointer;
    margin: 0;
}

/* ===== BUTTONS ===== */
.btn-create, .btn-wg, .btn-regen, .btn-submit,
.btn-assign, .btn-delete, .btn-small, .btn-select-all,
.copy-btn, .btn-rename {
    display: inline-flex;
    align-items: center;
    justify-content: center;
    gap: 6px;
    font-family: inherit;
    font-weight: 500;
    border-radius: var(--radius-sm);
    cursor: pointer;
    border: 1px solid transparent;
    text-decoration: none;
    white-space: nowrap;
    transition: background 0.15s, border-color 0.15s, color 0.15s, box-shadow 0.15s;
}
.btn-create:focus-visible, .btn-wg:focus-visible, .btn-regen:focus-visible,
.btn-submit:focus-visible, .btn-assign:focus-visible, .btn-delete:focus-visible,
.btn-small:focus-visible, .btn-select-all:focus-visible,
.copy-btn:focus-visible, .btn-rename:focus-visible {
    outline: none;
    box-shadow: var(--ring);
}

/* Primary */
.btn-create, .btn-wg, .btn-regen, .btn-submit {
    padding: 9px 18px;
    font-size: 13.5px;
    background: var(--primary);
    color: #fff;
    box-shadow: var(--shadow-xs);
}
.btn-create:hover, .btn-wg:hover, .btn-regen:hover, .btn-submit:hover {
    background: var(--primary-hover);
}
.btn-create:active, .btn-wg:active, .btn-regen:active, .btn-submit:active {
    background: var(--primary-active);
}
.btn-regen { margin-top: var(--sp-4); }

/* Success / assign */
.btn-assign {
    padding: 9px 20px;
    font-size: 13.5px;
    background: var(--success);
    color: #fff;
    box-shadow: var(--shadow-xs);
}
.btn-assign:hover { background: var(--success-strong); }

/* Danger (outline) */
.btn-delete {
    padding: 5px 12px;
    font-size: 12.5px;
    background: var(--surface);
    color: var(--danger);
    border-color: var(--danger-border);
}
.btn-delete:hover {
    background: var(--danger);
    border-color: var(--danger);
    color: #fff;
}
.btn-delete.btn-neutral {
    color: var(--gray-600);
    border-color: var(--border-strong);
}
.btn-delete.btn-neutral:hover {
    background: var(--danger);
    border-color: var(--danger);
    color: #fff;
}

/* Secondary small (panel headers, toolbars) */
.btn-small, .btn-select-all {
    padding: 4px 10px;
    font-size: 12px;
    background: var(--surface);
    color: var(--gray-700);
    border-color: var(--border-strong);
}
.btn-small:hover, .btn-select-all:hover {
    background: var(--gray-50);
    border-color: var(--gray-400);
    color: var(--gray-900);
}

/* Copy / inline action */
.copy-btn {
    padding: 4px 12px;
    font-size: 12px;
    background: var(--surface);
    color: var(--gray-700);
    border-color: var(--border-strong);
}
.copy-btn:hover { background: var(--gray-50); color: var(--gray-900); }
.copy-btn.copied {
    background: var(--success-soft);
    border-color: var(--success-border);
    color: var(--success-text);
}
.copy-btn.copy-btn-dl {
    background: var(--success);
    border-color: var(--success);
    color: #fff;
}
.copy-btn.copy-btn-dl:hover { background: var(--success-strong); }

/* Rename (icon button) */
.btn-rename {
    padding: 4px 9px;
    font-size: 12px;
    background: var(--surface);
    color: var(--gray-600);
    border-color: var(--border-strong);
}
.btn-rename:hover { color: var(--primary); border-color: var(--primary-border); background: var(--primary-soft); }

/* Size modifiers */
.btn-xs { padding: 3px 10px !important; font-size: 12px !important; }
.btn-inline { width: auto; }

/* Inline mini input (rename) */
.input-inline {
    width: 120px !important;
    padding: 4px 8px !important;
    font-size: 12px !important;
}

/* Entry remove (×) */
.entry-remove {
    border: none;
    background: transparent;
    color: var(--gray-400);
    font-size: 16px;
    line-height: 1;
    cursor: pointer;
    padding: 4px 6px;
    border-radius: var(--radius-sm);
    transition: color 0.15s, background 0.15s;
}
.entry-remove:hover { color: var(--danger); background: var(--danger-soft); }
.entry-remove:focus-visible { outline: none; box-shadow: var(--ring); }

/* ===== BADGES & CHIPS ===== */
.badge {
    display: inline-flex;
    align-items: center;
    padding: 2px 8px;
    border-radius: var(--radius-full);
    font-size: 11px;
    font-weight: 600;
    letter-spacing: 0.2px;
    background: var(--gray-100);
    color: var(--gray-600);
    border: 1px solid var(--gray-200);
    line-height: 1.5;
}
.badge-vrf {
    background: var(--accent-teal-soft);
    color: var(--accent-teal);
    border-color: var(--accent-teal-border);
}
.badge-wg {
    background: var(--accent-violet-soft);
    color: var(--accent-violet);
    border-color: var(--accent-violet-border);
}
.badge-type {
    background: var(--gray-100);
    color: var(--gray-500);
    border-color: var(--gray-200);
    font-size: 10px;
    text-transform: uppercase;
    letter-spacing: 0.4px;
}

.chip {
    display: inline-flex;
    align-items: center;
    gap: 5px;
    padding: 3px 10px;
    border-radius: var(--radius-full);
    font-size: 12px;
    font-weight: 500;
    border: 1px solid;
}
.chip-ok {
    background: var(--success-soft);
    color: var(--success-text);
    border-color: var(--success-border);
}
.chip-warn {
    background: var(--warning-soft);
    color: var(--warning-text);
    border-color: var(--warning-border);
}

/* ===== TABLES ===== */
table {
    width: 100%;
    border-collapse: collapse;
    margin: var(--sp-4) 0;
    font-size: 13px;
}
th {
    text-align: left;
    padding: 9px 12px;
    font-size: 11px;
    font-weight: 600;
    text-transform: uppercase;
    letter-spacing: 0.6px;
    color: var(--gray-500);
    background: var(--gray-50);
    border-bottom: 1px solid var(--border);
}
th:first-child { border-top-left-radius: var(--radius-sm); }
th:last-child { border-top-right-radius: var(--radius-sm); }
td {
    padding: 10px 12px;
    border-bottom: 1px solid var(--gray-100);
    color: var(--gray-700);
    vertical-align: middle;
}
tbody tr:hover, table tr:hover td { background: var(--gray-25); }
table tr:hover th { background: var(--gray-50); }

/* ===== TABLEAUX TRIABLES ===== */
th.sortable {
    cursor: pointer;
    user-select: none;
    padding-right: 22px;
    position: relative;
}
th.sortable:hover { color: var(--gray-800); }
/* Chevron discret au survol : indique que la colonne est triable sans
   surcharger l'en-tete des colonnes non triees. */
th.sortable::after {
    content: '\2195';                      /* ↕ */
    position: absolute;
    right: 8px;
    opacity: 0;
    font-size: 10px;
    transition: opacity 0.15s;
}
th.sortable:hover::after { opacity: 0.45; }
th.sortable.sorted-asc::after  { content: '\25B2'; opacity: 1; }   /* ▲ */
th.sortable.sorted-desc::after { content: '\25BC'; opacity: 1; }   /* ▼ */
th.sortable.sorted-asc, th.sortable.sorted-desc { color: var(--primary); }

/* Colonne de cases a cocher : largeur minimale, centree */
th.col-check, td.col-check {
    width: 1%;
    white-space: nowrap;
    text-align: center;
    padding-right: 4px;
}

/* Barre d'actions groupees au-dessus d'un tableau */
.table-toolbar {
    display: flex;
    align-items: center;
    gap: var(--sp-3);
    flex-wrap: wrap;
    margin-top: var(--sp-3);
}
.table-toolbar button[disabled] {
    opacity: 0.45;
    cursor: not-allowed;
}

/* ===== WIREGUARD CONFIG ===== */
.wg-download-bar {
    display: flex;
    align-items: center;
    gap: var(--sp-3);
    flex-wrap: wrap;
    margin-bottom: var(--sp-4);
}
.wg-config-panel {
    margin-top: var(--sp-3);
    border: 1px solid var(--success-border);
    border-radius: var(--radius);
    background: var(--success-soft);
    padding: var(--sp-3) var(--sp-4);
}
.wg-config-head {
    display: flex;
    justify-content: space-between;
    align-items: center;
    gap: var(--sp-2);
    flex-wrap: wrap;
    margin-bottom: var(--sp-2);
}
.wg-config-head strong { color: var(--success-text); font-size: 13.5px; }
.wg-config-actions { display: flex; gap: var(--sp-2); }
/* La configuration n'est plus affichee : elle porte la cle privee du peer, qui
   n'a rien a faire a l'ecran (capture, epaule, partage d'ecran). Elle reste dans
   le DOM, hors champ, pour alimenter le bouton Copier — `display: none`
   empecherait la selection utilisee par le repli de copie. */
.wg-config-note {
    margin: var(--sp-1) 0 0;
    font-size: 12.5px;
    color: var(--success-text);
}
.visually-hidden {
    position: absolute;
    width: 1px;
    height: 1px;
    padding: 0;
    margin: -1px;
    overflow: hidden;
    clip: rect(0 0 0 0);
    white-space: pre;
    border: 0;
}

/* ===== VRF CHECKBOX LIST (creation peer WG) ===== */
.select-all-row { margin: var(--sp-2) 0 var(--sp-1); }
.select-all-pill {
    display: inline-flex;
    align-items: center;
    gap: var(--sp-2);
    padding: 6px 14px;
    border-radius: var(--radius-full);
    background: var(--primary-soft);
    border: 1px solid var(--primary-border);
    color: var(--primary);
    font-size: 12.5px;
    font-weight: 600;
    cursor: pointer;
    user-select: none;
    margin: 0;
    transition: background 0.15s;
}
.select-all-pill:hover { background: #e0e7ff; }
.vrf-check-list {
    display: flex;
    flex-direction: column;
    gap: var(--sp-2);
    margin-top: var(--sp-2);
}
.vrf-check-item {
    border: 1px solid var(--border);
    border-radius: var(--radius);
    padding: var(--sp-3) var(--sp-4);
    background: var(--gray-25);
    transition: border-color 0.15s, background 0.15s;
}
.vrf-check-item:hover { border-color: var(--border-strong); }
.vrf-check-label {
    display: flex;
    align-items: center;
    gap: var(--sp-3);
    cursor: pointer;
    margin: 0;
    font-weight: 500;
    font-size: 13.5px;
    color: var(--gray-800);
}
.vrf-check-port { color: var(--gray-400); font-size: 12px; font-weight: 400; }
.vrf-ip-row { margin-top: var(--sp-2); padding-left: 28px; }
.vrf-ip-info {
    font-size: 12px;
    color: var(--gray-500);
    font-family: var(--font-mono);
    margin-bottom: var(--sp-1);
}
.vrf-ip-row input[type="text"] {
    width: 200px;
    font-family: var(--font-mono);
    font-size: 13px;
    padding: 5px 10px;
}

/* ===== ASSIGN PANELS ===== */
.assign-panels {
    display: grid;
    grid-template-columns: 1fr 1fr;
    gap: var(--sp-5);
    margin: var(--sp-5) 0;
}
.assign-panel {
    border: 1px solid var(--border);
    border-radius: var(--radius-lg);
    overflow: hidden;
    display: flex;
    flex-direction: column;
    background: var(--surface);
}
.assign-panel-header {
    background: var(--gray-50);
    border-bottom: 1px solid var(--border);
    padding: var(--sp-3) var(--sp-4);
    display: flex;
    justify-content: space-between;
    align-items: center;
    gap: var(--sp-2);
    font-weight: 600;
    font-size: 13px;
    color: var(--gray-700);
    flex-shrink: 0;
}
.assign-panel-body {
    max-height: 440px;
    overflow-y: auto;
    padding: var(--sp-2);
    flex: 1;
}
.panel-toolbar { padding: var(--sp-1) var(--sp-2) var(--sp-2); }
.panel-empty {
    padding: var(--sp-6) var(--sp-4);
    text-align: center;
    color: var(--gray-500);
    font-size: 13px;
}
.panel-empty .btn-create { margin-top: var(--sp-3); }

/* ===== PEER / DEVICE CARDS ===== */
.peer-card, .device-card {
    display: flex;
    align-items: flex-start;
    gap: var(--sp-3);
    padding: 10px 12px;
    margin-bottom: var(--sp-2);
    border: 1px solid var(--border);
    border-radius: var(--radius);
    cursor: pointer;
    transition: border-color 0.15s, background 0.15s, box-shadow 0.15s;
    background: var(--surface);
    user-select: none;
}
.peer-card:hover, .device-card:hover {
    border-color: var(--primary-border);
    background: var(--gray-25);
}
.peer-card.selected, .device-card.selected {
    border-color: var(--primary);
    background: var(--primary-soft);
    box-shadow: inset 0 0 0 1px var(--primary);
}
.peer-card input[type="checkbox"],
.device-card input[type="checkbox"] { margin-top: 2px; }
.peer-card-content, .device-card-content { flex: 1; min-width: 0; }
.peer-card-name {
    font-weight: 600;
    font-size: 13.5px;
    color: var(--gray-800);
    white-space: nowrap;
    overflow: hidden;
    text-overflow: ellipsis;
}
.device-card-name {
    font-weight: 600;
    font-size: 13px;
    color: var(--gray-800);
    display: flex;
    align-items: center;
    gap: 6px;
    flex-wrap: wrap;
}
.peer-card-meta, .device-card-meta {
    font-size: 12px;
    color: var(--gray-500);
    margin-top: 3px;
    display: flex;
    gap: var(--sp-2);
    align-items: center;
    flex-wrap: wrap;
}
.device-card-meta em { color: var(--gray-400); font-style: italic; }

/* ===== VRF ACCORDION (panneau devices) ===== */
.vrf-section { margin-bottom: var(--sp-2); }
.vrf-section-header {
    display: flex;
    align-items: center;
    gap: var(--sp-2);
    padding: 8px 10px;
    background: var(--gray-50);
    border: 1px solid var(--border);
    border-radius: var(--radius-sm);
    cursor: pointer;
    font-size: 13px;
    user-select: none;
    transition: background 0.15s, border-color 0.15s;
}
.vrf-section-header:hover { background: var(--gray-100); border-color: var(--border-strong); }
.vrf-section-count { font-weight: 600; color: var(--gray-600); font-size: 12.5px; }
.vrf-toggle {
    margin-left: auto;
    color: var(--gray-400);
    font-size: 11px;
}
.vrf-section-body { padding: var(--sp-2) 0 2px; }
.vrf-section-body.collapsed { display: none; }

/* ===== ASSIGN FOOTER ===== */
.assign-footer {
    display: flex;
    gap: var(--sp-4);
    align-items: flex-end;
    margin-top: var(--sp-5);
    padding: var(--sp-4);
    background: var(--gray-50);
    border: 1px solid var(--border);
    border-radius: var(--radius-lg);
    flex-wrap: wrap;
}
.assign-footer-grade { flex: 1; min-width: 220px; }
.assign-footer-grade label { margin-bottom: var(--sp-2); }
.assign-footer-info {
    font-size: 13px;
    color: var(--gray-500);
    white-space: nowrap;
    padding-bottom: 9px;
}
.assign-footer-info span { font-weight: 600; color: var(--gray-700); }

/* ===== ASSOCIATIONS (Autorisations) ===== */
.list-card {
    background: var(--surface);
    border: 1px solid var(--border);
    border-radius: var(--radius-lg);
    padding: var(--sp-4) var(--sp-5);
    margin-bottom: var(--sp-4);
    box-shadow: var(--shadow-xs);
}
.list-card.grade-ok { border-left: 3px solid var(--success); }
.list-card.grade-warn { border-left: 3px solid var(--warning); }

.grade-header {
    display: flex;
    justify-content: space-between;
    align-items: center;
    flex-wrap: wrap;
    gap: var(--sp-2);
    padding-bottom: var(--sp-3);
    border-bottom: 1px solid var(--gray-100);
    margin-bottom: var(--sp-3);
}
.grade-title { font-size: 14px; font-weight: 600; color: var(--gray-900); }
.grade-vrfs { font-size: 12px; color: var(--gray-500); margin-left: var(--sp-2); }
.grade-actions {
    display: flex;
    align-items: center;
    gap: var(--sp-2);
    flex-wrap: wrap;
}

.assoc-grid {
    display: grid;
    grid-template-columns: 1fr 1fr;
    gap: var(--sp-4);
    margin-bottom: var(--sp-3);
}
.assoc-summary {
    font-size: 12.5px;
    font-weight: 500;
    color: var(--primary);
    cursor: pointer;
    user-select: none;
    padding: 4px 0;
}
.assoc-summary:hover { color: var(--primary-hover); }
details[open] > .assoc-summary { margin-bottom: var(--sp-2); }
.assoc-form { margin-top: var(--sp-2); }
.assoc-selector {
    max-height: 190px;
    overflow: auto;
    border: 1px solid var(--border);
    border-radius: var(--radius-sm);
    padding: var(--sp-2) var(--sp-3);
    background: var(--surface);
}
.assoc-item {
    display: flex;
    align-items: center;
    gap: var(--sp-2);
    margin: 2px 0;
    padding: 3px 4px;
    border-radius: 4px;
    font-size: 12.5px;
    font-weight: 400;
    color: var(--gray-700);
    cursor: pointer;
}
.assoc-item:hover { background: var(--gray-50); }
.assoc-item-label { font-weight: 500; }
.assoc-item-meta {
    margin-left: auto;
    font-size: 11px;
    color: var(--gray-400);
    font-family: var(--font-mono);
}
.assoc-item-nested { padding-left: var(--sp-2); }
.assoc-group-title {
    font-size: 11px;
    font-weight: 600;
    text-transform: uppercase;
    letter-spacing: 0.5px;
    margin: var(--sp-2) 0 2px;
    color: var(--gray-500);
}
.assoc-validate { margin-top: var(--sp-2); width: 100%; }

/* Colonnes Sources / Destinations */
.entries-grid {
    display: grid;
    grid-template-columns: 1fr 1fr;
    gap: var(--sp-4);
    margin-top: var(--sp-2);
}
.col-title {
    font-size: 11px;
    font-weight: 600;
    text-transform: uppercase;
    letter-spacing: 0.6px;
    margin-bottom: var(--sp-2);
}
.col-title.col-src { color: var(--primary); }
.col-title.col-dst { color: var(--danger); }

/* Colonnes Sources / Destinations repliables : sans cela une association de
   plusieurs dizaines d'entrees etire la page sur des ecrans entiers. */
.entries-panel { min-width: 0; }
.entries-summary {
    display: flex;
    align-items: center;
    gap: var(--sp-2);
    cursor: pointer;
    user-select: none;
    padding: 4px 0;
    list-style: none;
}
.entries-summary::-webkit-details-marker { display: none; }
.entries-summary::before {
    content: '\25B8';                      /* ▸ */
    font-size: 10px;
    line-height: 1;
    transition: transform 0.15s ease;
}
.entries-panel[open] > .entries-summary::before { transform: rotate(90deg); }
.entries-summary:hover { filter: brightness(0.85); }
.entry-count {
    font-size: 10px;
    font-weight: 600;
    letter-spacing: 0;
    color: var(--gray-600);
    background: var(--gray-100);
    border-radius: var(--radius-full);
    padding: 1px 7px;
}
.entries-body {
    max-height: 320px;
    overflow: auto;
    border: 1px solid var(--border);
    border-radius: var(--radius-sm);
    padding: 0 var(--sp-3);
    background: var(--surface);
}
.entries-body::-webkit-scrollbar { width: 8px; }
.entries-body::-webkit-scrollbar-track { background: transparent; }
.entries-body::-webkit-scrollbar-thumb {
    background: var(--gray-300);
    border-radius: var(--radius-full);
}
.entries-body::-webkit-scrollbar-thumb:hover { background: var(--gray-400); }
.entry-row {
    display: flex;
    justify-content: space-between;
    align-items: center;
    gap: var(--sp-2);
    padding: 6px 0;
    border-bottom: 1px solid var(--gray-100);
}
.entry-row:last-of-type { border-bottom: none; }
.entry-name {
    font-size: 13px;
    font-weight: 500;
    color: var(--gray-800);
}
.entry-vrf { color: var(--gray-400); font-size: 11px; font-weight: 400; }
.entry-ip { font-size: 11px; color: var(--gray-500); }
.entry-ip code { font-size: 11px; margin-left: 4px; }

/* Groupes VRF repliables dans les colonnes Sources / Destinations (meme
   presentation que les sections VRF de l'onglet Assignation). L'en-tete reste
   colle en haut de la zone scrollable : on sait toujours quelle VRF on lit. */
.entries-vrf-section { margin: var(--sp-2) 0; }
.entries-vrf-section .vrf-section-header {
    position: sticky;
    top: 0;
    z-index: 1;
}
.entries-vrf-section .vrf-section-body { padding: 2px 0 0; }
.empty-entries {
    color: var(--gray-400);
    font-size: 13px;
    font-style: italic;
    padding: var(--sp-2) 0;
}

/* ===== WG USER TREE ===== */
.wg-user-tree {
    display: flex;
    flex-direction: column;
    gap: var(--sp-3);
}
.wg-user-card {
    border: 1px solid var(--border);
    border-radius: var(--radius);
    background: var(--surface);
    overflow: hidden;
}
.wg-user-header {
    display: flex;
    justify-content: space-between;
    align-items: center;
    gap: var(--sp-2);
    flex-wrap: wrap;
    padding: var(--sp-3) var(--sp-4);
    cursor: pointer;
    background: var(--gray-25);
    transition: background 0.15s;
}
.wg-user-header:hover { background: var(--gray-50); }
.wg-user-title { display: flex; flex-direction: column; min-width: 0; }
.wg-user-name { font-weight: 600; font-size: 14px; color: var(--gray-900); }
.wg-user-count { font-size: 11.5px; color: var(--gray-500); }
.wg-user-actions {
    display: flex;
    align-items: center;
    gap: var(--sp-2);
    flex-wrap: wrap;
}
.wg-user-toggle { font-size: 12px; color: var(--gray-400); padding: 0 var(--sp-1); }
.wg-user-details {
    padding: 0 var(--sp-4) var(--sp-3);
    border-top: 1px solid var(--gray-100);
}
.rename-form {
    margin: 0;
    display: inline-flex;
    align-items: center;
    gap: var(--sp-1);
}
.vrf-actions {
    display: flex;
    align-items: center;
    gap: var(--sp-2);
    flex-wrap: wrap;
}

/* ===== SCROLLBARS ===== */
.assign-panel-body::-webkit-scrollbar,
.assoc-selector::-webkit-scrollbar,
.tabs::-webkit-scrollbar { width: 8px; height: 8px; }
.assign-panel-body::-webkit-scrollbar-track,
.assoc-selector::-webkit-scrollbar-track,
.tabs::-webkit-scrollbar-track { background: transparent; }
.assign-panel-body::-webkit-scrollbar-thumb,
.assoc-selector::-webkit-scrollbar-thumb,
.tabs::-webkit-scrollbar-thumb {
    background: var(--gray-300);
    border-radius: var(--radius-full);
}
.assign-panel-body::-webkit-scrollbar-thumb:hover,
.assoc-selector::-webkit-scrollbar-thumb:hover { background: var(--gray-400); }

/* ===== LOGIN / CONFIG PAGE ===== */
body.login-body {
    min-height: 100vh;
    display: flex;
    justify-content: center;
    align-items: center;
    background: var(--gray-50);
    background-image: radial-gradient(circle at 1px 1px, var(--gray-200) 1px, transparent 0);
    background-size: 24px 24px;
    padding: var(--sp-5);
}
.login-container {
    background: var(--surface);
    border: 1px solid var(--border);
    border-radius: var(--radius-lg);
    box-shadow: var(--shadow-md);
    padding: var(--sp-8);
    width: 100%;
    max-width: 460px;
}
.login-brand {
    display: flex;
    align-items: center;
    gap: var(--sp-3);
    margin-bottom: var(--sp-5);
}
.login-container h2 {
    font-size: 17px;
    font-weight: 600;
    margin-bottom: var(--sp-3);
    letter-spacing: -0.2px;
}
.login-container p {
    font-size: 13.5px;
    color: var(--gray-600);
    margin-bottom: var(--sp-3);
}
.error-msg {
    background: var(--danger-soft);
    border: 1px solid var(--danger-border);
    color: var(--danger-text) !important;
    border-radius: var(--radius);
    padding: var(--sp-3) var(--sp-4);
}

/* ===== UTILITIES ===== */
.inline-form { display: inline; margin: 0; }
.m-0 { margin: 0; }

/* ===== RESPONSIVE ===== */
@media (max-width: 900px) {
    .assign-panels,
    .assoc-grid,
    .entries-grid { grid-template-columns: 1fr; }
}
@media (max-width: 640px) {
    .topbar-inner { flex-wrap: wrap; padding: var(--sp-3) var(--sp-4); }
    .conn-status { order: 3; width: 100%; margin-left: 0; }
    .page-main { padding: var(--sp-4) var(--sp-3) 48px; }
    .container { padding: var(--sp-4); border-radius: var(--radius); }
    .assign-footer { align-items: stretch; flex-direction: column; }
    .assign-footer-info { padding-bottom: 0; }
    .grade-header { align-items: flex-start; flex-direction: column; }
    .wg-user-details { overflow-x: auto; }
    .wg-user-details table { min-width: 560px; }
}

/* ===== BANDEAU VUE D'ENSEMBLE ===== */
.overview-bar {
    display: flex;
    flex-wrap: wrap;
    align-items: center;
    gap: var(--sp-4);
    background: var(--gray-50);
    border: 1px solid var(--border);
    border-radius: var(--radius);
    padding: var(--sp-3) var(--sp-4);
    margin-bottom: var(--sp-5);
    font-size: 13px;
    color: var(--gray-600);
}
.overview-item { white-space: nowrap; }
.overview-num {
    font-size: 15px;
    font-weight: 700;
    color: var(--gray-800);
    margin-right: 2px;
}
.overview-warn,
.overview-warn .overview-num { color: #b45309; }
.overview-item-right { margin-left: auto; }

/* ===== BADGE CONNEXION ABSENTE ===== */
.conn-status-off { opacity: 0.75; }
.conn-dot-off { background: #dc2626 !important; }

/* ===== CHAMPS DE RECHERCHE / FILTRE ===== */
.filter-input {
    border: 1px solid var(--border);
    border-radius: var(--radius);
    padding: var(--sp-2) var(--sp-3);
    font-size: 13px;
    min-width: 200px;
}
.filter-input:focus {
    outline: none;
    border-color: var(--primary-border);
}
.panel-toolbar {
    display: flex;
    align-items: center;
    gap: var(--sp-2);
    flex-wrap: wrap;
    margin-bottom: var(--sp-2);
}
.panel-toolbar .filter-input { flex: 1; min-width: 140px; }

/* ===== SELECT GRADE (onglet Assignation) ===== */
.assign-footer-grade select {
    border: 1px solid var(--border);
    border-radius: var(--radius);
    padding: var(--sp-2) var(--sp-3);
    font-size: 13px;
    background: #fff;
}
#assign_grade_new { margin-top: var(--sp-1); }

/* ===== APERCU VRF : erreur doublon ===== */
.field-hint-error { color: #b91c1c; font-weight: 600; }

/* ===== ONGLET REGENERER : actions ===== */
.rules-actions {
    display: flex;
    align-items: center;
    gap: var(--sp-3);
    flex-wrap: wrap;
    margin: var(--sp-4) 0;
}

/* ===== JOURNAL DES ACTIONS ===== */
.journal-table { width: 100%; }
.journal-table td, .journal-table th { font-size: 12.5px; }
.journal-details { color: var(--gray-600); word-break: break-word; }

/* ===== MODALE DE CONFIRMATION ===== */
.modal-overlay {
    position: fixed;
    inset: 0;
    background: rgba(15, 23, 42, 0.55);
    display: flex;
    align-items: center;
    justify-content: center;
    z-index: 1000;
    padding: var(--sp-4);
}
.modal-box {
    background: #fff;
    border-radius: var(--radius);
    border: 1px solid var(--border);
    box-shadow: 0 20px 50px rgba(0,0,0,0.25);
    padding: var(--sp-5);
    max-width: 480px;
    width: 100%;
}
.modal-box h4 {
    font-size: 16px;
    font-weight: 700;
    margin-bottom: var(--sp-3);
}
.modal-summary {
    margin: 0 0 var(--sp-3) 0;
    padding-left: var(--sp-5);
    font-size: 13.5px;
    line-height: 1.6;
}
.modal-warning {
    font-size: 12.5px;
    color: #b45309;
    font-weight: 600;
    margin-bottom: var(--sp-4);
}
.modal-actions {
    display: flex;
    justify-content: flex-end;
    gap: var(--sp-3);
}
.modal-actions .btn-neutral {
    background: var(--gray-50);
    border: 1px solid var(--border);
    border-radius: var(--radius);
    padding: var(--sp-2) var(--sp-4);
    font-size: 13px;
    cursor: pointer;
}

/* ===== Droits par peer (onglet Assignation) : sans limite / date limite ===== */
.peer-card-exp {
    display: none;
    align-items: center;
    gap: 6px;
    margin-left: auto;
    flex-shrink: 0;
}
.peer-card.selected .peer-card-exp { display: flex; }
.peer-card-exp select,
.peer-card-exp input[type="date"] {
    font-size: 12px;
    padding: 3px 6px;
    border: 1px solid var(--border);
    border-radius: 6px;
    background: #fff;
    color: var(--gray-800);
}

/* ===== Topbar : chip utilisateur SSO + bouton connexion ===== */
.user-chip {
    display: inline-flex;
    align-items: center;
    gap: 6px;
    margin-left: var(--sp-2);
    padding: 4px 12px;
    border: 1px solid var(--primary-border);
    border-radius: var(--radius-full);
    background: var(--primary-soft);
    font-size: 12.5px;
    font-weight: 600;
    color: var(--primary);
    white-space: nowrap;
    max-width: 220px;
    overflow: hidden;
    text-overflow: ellipsis;
}
.user-chip-icon { font-size: 11px; line-height: 1; }
.logout-btn-accent {
    color: var(--primary);
    border-color: var(--primary-border);
    background: var(--primary-soft);
}
.logout-btn-accent:hover { background: var(--primary-soft); border-color: var(--primary); }

/* ===== Page de connexion (login.html) ===== */
.login-card {
    max-width: 420px;
    margin: 9vh auto;
    padding: var(--sp-6) var(--sp-5);
    background: var(--surface);
    border: 1px solid var(--border);
    border-radius: var(--radius-md, 12px);
    box-shadow: 0 8px 30px rgba(15, 23, 42, 0.06);
    text-align: center;
}
.login-brand { justify-content: center; margin-bottom: var(--sp-4); }
.login-title { margin-bottom: var(--sp-4); }
/* Bouton de connexion Microsoft Entra ID : fond sombre et logo en quatre
   carrés, conformément aux règles de marque Microsoft pour « Se connecter avec ». */
.btn-ms {
    display: inline-flex;
    align-items: center;
    justify-content: center;
    gap: 10px;
    width: 100%;
    padding: 12px 16px;
    font-size: 14.5px;
    font-weight: 600;
    color: #fff;
    background: #2f2f2f;
    border: 1px solid #1f1f1f;
    border-radius: var(--radius-sm);
    text-decoration: none;
    cursor: pointer;
    transition: background 0.15s, box-shadow 0.15s;
}
.btn-ms:hover { background: #1f1f1f; }
.btn-ms:focus-visible { outline: none; box-shadow: var(--ring); }
.btn-ms-logo {
    display: grid;
    grid-template-columns: repeat(2, 9px);
    grid-template-rows: repeat(2, 9px);
    gap: 2px;
}
.ms-sq { display: block; width: 9px; height: 9px; background: currentColor; }
.ms-sq-r { background: #f25022; }
.ms-sq-g { background: #7fba00; }
.ms-sq-b { background: #00a4ef; }
.ms-sq-y { background: #ffb900; }
.btn-ms-disabled {
    background: var(--gray-200, #e5e7eb);
    border-color: var(--border);
    color: var(--gray-500);
    cursor: not-allowed;
}
.btn-ms-disabled .ms-sq { background: rgba(0, 0, 0, 0.15); }
.login-divider {
    display: flex;
    align-items: center;
    gap: var(--sp-3);
    margin: var(--sp-4) 0;
    color: var(--gray-400);
    font-size: 12px;
}
.login-divider::before, .login-divider::after {
    content: "";
    flex: 1;
    height: 1px;
    background: var(--border);
}
.login-direct { width: 100%; box-sizing: border-box; }
.login-note {
    margin-top: var(--sp-3);
    font-size: 12px;
    color: var(--gray-500);
    line-height: 1.5;
}

/* ===== Indicateur de securite du transport MikroTik (topbar) ===== */
.conn-sec { margin-left: 4px; font-size: 12px; line-height: 1; }
.conn-sec-ok   { color: var(--success); }
.conn-sec-warn { color: #d97706; }

/* ===================================================================== */
/* Indicateurs de chargement                                             */
/* ===================================================================== */

/* Rond qui tourne, reutilisable. Taille pilotee par font-size du parent. */
.spinner {
    display: inline-block;
    width: 1em;
    height: 1em;
    border: 2px solid var(--primary-border);
    border-top-color: var(--primary);
    border-radius: 50%;
    animation: spinner-rotate 0.6s linear infinite;
    vertical-align: -0.15em;
    flex: none;
}
.spinner-sm { width: 0.85em; height: 0.85em; border-width: 2px; }
.spinner-lg { width: 34px; height: 34px; border-width: 3px; }

@keyframes spinner-rotate { to { transform: rotate(360deg); } }

/* Spinner inline accompagne d'un libelle (retour AJAX) */
.loading-inline {
    display: inline-flex;
    align-items: center;
    gap: 6px;
    color: var(--gray-500);
}

/* Voile plein ecran pendant une action serveur (appels MikroTik lents) */
.loading-overlay {
    position: fixed;
    inset: 0;
    z-index: 9999;
    display: flex;
    align-items: center;
    justify-content: center;
    background: rgba(15, 23, 42, 0.45);
    backdrop-filter: blur(2px);
    opacity: 0;
    visibility: hidden;
    transition: opacity 0.15s ease, visibility 0.15s ease;
}
.loading-overlay.is-visible { opacity: 1; visibility: visible; }

.loading-box {
    display: flex;
    flex-direction: column;
    align-items: center;
    gap: var(--sp-3);
    padding: 26px 34px;
    background: #fff;
    border: 1px solid var(--border);
    border-radius: 12px;
    box-shadow: 0 18px 40px rgba(15, 23, 42, 0.22);
    max-width: 320px;
    text-align: center;
}
.loading-box-title { font-size: 14px; font-weight: 600; color: var(--gray-800); }
.loading-box-hint  { font-size: 12px; color: var(--gray-500); line-height: 1.5; }

/* Bouton en cours d'envoi : spinner a la place du libelle */
button.is-loading { position: relative; color: transparent !important; pointer-events: none; }
button.is-loading::after {
    content: "";
    position: absolute;
    top: 50%; left: 50%;
    width: 14px; height: 14px;
    margin: -7px 0 0 -7px;
    border: 2px solid rgba(255, 255, 255, 0.45);
    border-top-color: #fff;
    border-radius: 50%;
    animation: spinner-rotate 0.6s linear infinite;
}
button.btn-small.is-loading::after,
button.btn-select-all.is-loading::after {
    border-color: var(--primary-border);
    border-top-color: var(--primary);
}

@media (prefers-reduced-motion: reduce) {
    .spinner, button.is-loading::after { animation-duration: 2s; }
    .loading-overlay { transition: none; }
}

/* ===== Date d'expiration par utilisateur (onglet Autorisations) ===== */
.assoc-item-exp {
    display: flex;
    align-items: center;
    gap: var(--sp-2);
}
.assoc-item-exp .assoc-item-label { flex: 1; min-width: 0; }

.assoc-item-date {
    display: inline-flex;
    align-items: center;
    gap: 4px;
    flex: none;
}
.exp-date-input {
    font-size: 12px;
    padding: 3px 6px;
    border: 1px solid var(--border);
    border-radius: 6px;
    background: #fff;
    color: var(--gray-700);
    width: 140px;
}
.exp-date-input:focus {
    outline: none;
    border-color: var(--primary);
    box-shadow: 0 0 0 2px var(--primary-soft);
}
/* Une date vide se lit comme "sans limite" : on l'attenue pour que les acces
   reellement limites ressortent dans la liste. */
.exp-date-input:invalid,
.exp-date-input:placeholder-shown { color: var(--gray-400); }


/* ===================================================================== */
/* Bulles d'aide par onglet                                              */
/* ===================================================================== */
/* Un simple "?" a cote du titre. Le contenu s'ouvre en surcouche ancree,
   sans pousser la mise en page ni occuper la largeur de la page. */

.help-wrap { position: relative; display: inline-block; vertical-align: middle; }

.help-badge {
    width: 20px;
    height: 20px;
    margin-left: var(--sp-2);
    border: 1px solid var(--primary-border);
    background: var(--primary-soft);
    color: var(--primary);
    border-radius: 50%;
    font-size: 12px;
    font-weight: 700;
    line-height: 1;
    cursor: pointer;
    padding: 0;
    display: inline-flex;
    align-items: center;
    justify-content: center;
}
.help-badge:hover        { background: var(--primary); color: #fff; }
.help-badge[aria-expanded="true"] { background: var(--primary); color: #fff; }

.help-pop {
    display: none;
    position: absolute;
    top: calc(100% + 8px);
    left: 0;
    z-index: 200;
    width: 400px;
    max-width: calc(100vw - 32px);
    max-height: min(560px, 70vh);
    overflow-y: auto;
    padding: var(--sp-4);
    background: #fff;
    border: 1px solid var(--border);
    border-radius: 10px;
    box-shadow: 0 12px 32px rgba(15, 23, 42, 0.18);
    font-size: 13px;
    font-weight: 400;
    line-height: 1.55;
    color: var(--gray-700);
    text-align: left;
    white-space: normal;
}
.help-pop.is-open { display: block; }

/* Petite fleche vers le badge */
.help-pop::before {
    content: "";
    position: absolute;
    top: -5px;
    left: var(--help-arrow, 14px);
    width: 8px;
    height: 8px;
    background: #fff;
    border-left: 1px solid var(--border);
    border-top: 1px solid var(--border);
    transform: rotate(45deg);
}

.help-pop h5 {
    margin: 0 0 var(--sp-2);
    font-size: 13px;
    font-weight: 700;
    color: var(--gray-900);
}
.help-pop p  { margin: 0 0 var(--sp-2); }
.help-pop ul { margin: 0 0 var(--sp-2); padding-left: 18px; }
.help-pop li { margin-bottom: 4px; }
.help-pop code {
    background: var(--gray-100);
    padding: 1px 4px;
    border-radius: 4px;
    font-size: 12px;
}
.help-pop > :last-child { margin-bottom: 0; }
.help-pop-note {
    margin-top: var(--sp-3);
    padding-top: var(--sp-2);
    border-top: 1px solid var(--border);
    font-size: 12px;
    color: var(--gray-500);
}


/* ===================================================================== */
/* Selecteur d'equipements par blocs (onglet Autorisations)              */
/* ===================================================================== */
/* Un parc de plusieurs centaines de sites tenait dans une seule liste
   deroulante : impraticable. Un bloc repliable par projet, plus une
   recherche, rendent la selection navigable. */

.dev-picker { display: flex; flex-direction: column; gap: var(--sp-2); }

.dev-picker-toolbar {
    display: flex;
    align-items: center;
    gap: var(--sp-2);
}
.dev-picker-toolbar .dev-search { flex: 1; min-width: 0; }
.dev-picker-empty {
    font-size: 12px;
    color: var(--danger, #dc2626);
    white-space: nowrap;
}
.dev-fold { flex: none; white-space: nowrap; }

.dev-picker-body { max-height: 340px; overflow-y: auto; }

.dev-block { border-bottom: 1px solid var(--border); }
.dev-block:last-child { border-bottom: 0; }
.dev-block[hidden] { display: none; }

.dev-block-head {
    display: flex;
    align-items: center;
    gap: var(--sp-2);
    padding: 7px var(--sp-3);
    cursor: pointer;
    list-style: none;
    background: var(--gray-50);
    position: sticky;
    top: 0;
    z-index: 1;
}
.dev-block-head::-webkit-details-marker { display: none; }
.dev-block-head::before {
    content: "▸";
    font-size: 10px;
    color: var(--gray-400);
    flex: none;
    transition: transform 0.12s ease;
}
.dev-block[open] > .dev-block-head::before { transform: rotate(90deg); }
.dev-block-head:hover { background: var(--gray-100); }

.dev-block-name {
    flex: 1;
    font-size: 12px;
    font-weight: 700;
    text-transform: uppercase;
    letter-spacing: 0.03em;
    color: var(--gray-600);
    min-width: 0;
    overflow: hidden;
    text-overflow: ellipsis;
}
.dev-block-count {
    font-size: 11px;
    color: var(--gray-500);
    font-variant-numeric: tabular-nums;
    flex: none;
}
.dev-block-count .dev-block-sel { color: var(--primary); }

.dev-block-all {
    flex: none;
    font-size: 11px;
    color: var(--primary);
    border: 1px solid var(--primary-border);
    background: #fff;
    border-radius: 5px;
    padding: 1px 7px;
    cursor: pointer;
}
.dev-block-all:hover { background: var(--primary-soft); }

.dev-row[hidden] { display: none; }

/* ===== Temoin d'appel AJAX (coin bas-droit, non bloquant) ===== */
.ajax-beacon {
    position: fixed;
    right: 16px;
    bottom: 16px;
    z-index: 9998;
    display: flex;
    align-items: center;
    gap: 8px;
    padding: 8px 14px;
    background: #fff;
    border: 1px solid var(--border);
    border-radius: 999px;
    box-shadow: 0 8px 24px rgba(15, 23, 42, 0.16);
    font-size: 12px;
    color: var(--gray-700);
    opacity: 0;
    visibility: hidden;
    transform: translateY(6px);
    transition: opacity 0.15s ease, transform 0.15s ease, visibility 0.15s ease;
}
.ajax-beacon.is-visible { opacity: 1; visibility: visible; transform: translateY(0); }

.spinner.control-busy { margin-left: 8px; }

/* ===================================================================== */
/* ===  RAFFINEMENT VISUEL — inspiration Apple (couche de surcharge)  === */
/* ===================================================================== */
/* Ajoutee en fin de fichier : re-tokenise la palette et affine les
   composants cles vers un rendu epure, clair et moderne. Aucune structure
   HTML modifiee — uniquement l'apparence. */

:root {
    /* Bleu systeme, gris quasi neutres facon macOS */
    --primary:        #0071e3;
    --primary-hover:  #0077ed;
    --primary-active: #006edb;
    --primary-soft:   #e8f2fd;
    --primary-border: #a9d2f7;

    --gray-25:  #ffffff;
    --gray-50:  #f5f5f7;
    --gray-100: #ececee;
    --gray-200: #e3e3e6;
    --gray-300: #d2d2d7;
    --gray-400: #a1a1a6;
    --gray-500: #6e6e73;
    --gray-600: #515154;
    --gray-700: #3a3a3c;
    --gray-800: #1d1d1f;
    --gray-900: #000000;

    --success:        #34c759;
    --success-strong: #248a3d;
    --success-soft:   #ecfaef;
    --success-border: #b7ebc3;
    --success-text:   #1c7a34;

    --danger:        #ff3b30;
    --danger-hover:  #e0322a;
    --danger-soft:   #fdecec;
    --danger-border: #f7c4c1;
    --danger-text:   #c4291f;

    --warning:        #ff9500;
    --warning-soft:   #fff5e6;
    --warning-border: #ffd8a1;
    --warning-text:   #9a5b00;

    --info-soft:   #e8f2fd;
    --info-border: #a9d2f7;
    --info-text:   #0058b0;

    --accent-teal:        #00a3a3;
    --accent-teal-soft:   #e6f7f7;
    --accent-teal-border: #a5e5e5;
    --accent-violet:        #5e5ce6;
    --accent-violet-soft:   #eeeefc;
    --accent-violet-border: #c9c8f5;

    --bg:            #f5f5f7;
    --surface:       #ffffff;
    --border:        rgba(0, 0, 0, 0.08);
    --border-strong: rgba(0, 0, 0, 0.16);

    /* Rayons plus genereux, ombres plus douces et diffuses */
    --radius-sm: 8px;
    --radius:    11px;
    --radius-lg: 18px;

    --shadow-xs: 0 1px 2px rgba(0, 0, 0, 0.04);
    --shadow-sm: 0 2px 8px rgba(0, 0, 0, 0.05);
    --shadow-md: 0 8px 28px rgba(0, 0, 0, 0.08);

    --ring: 0 0 0 4px rgba(0, 113, 227, 0.28);

    --content-width: 1120px;

    --ease: cubic-bezier(0.4, 0, 0.2, 1);
}

body {
    font-size: 14.5px;
    letter-spacing: -0.01em;
    background:
        radial-gradient(1200px 600px at 50% -320px, rgba(0, 113, 227, 0.06), transparent 70%),
        var(--bg);
    background-attachment: fixed;
}

/* ---- Topbar : verre depoli translucide ---- */
.topbar {
    background: rgba(255, 255, 255, 0.72);
    -webkit-backdrop-filter: saturate(180%) blur(20px);
    backdrop-filter: saturate(180%) blur(20px);
    border-bottom: 1px solid var(--border);
}
.topbar-inner { padding-top: var(--sp-3); padding-bottom: var(--sp-3); }
.brand-mark {
    border-radius: 9px;
    background: linear-gradient(135deg, #0071e3 0%, #5e5ce6 100%);
    box-shadow: 0 2px 8px rgba(0, 113, 227, 0.32);
}
.brand-name { font-weight: 650; letter-spacing: -0.02em; }
.conn-status { background: rgba(0,0,0,0.03); backdrop-filter: blur(6px); }

/* ---- Onglets : controle segmente facon macOS ---- */
.tabs-bar {
    /* La barre est sticky : sans fond, les libelles (Devices, Autorisations...)
       se superposaient au texte qui defile dessous. Meme verre depoli que la
       topbar, avec laquelle elle forme un seul bandeau ; opacite quasi pleine
       pour rester lisible meme sans backdrop-filter. Pas de marge au-dessus
       des onglets : elle fusionnerait avec la barre et laisserait un jour
       transparent entre topbar et onglets. */
    background: rgba(245, 245, 247, 0.92);
    -webkit-backdrop-filter: saturate(180%) blur(20px);
    backdrop-filter: saturate(180%) blur(20px);
    border-bottom: 1px solid var(--border);
    position: sticky;
    top: 57px;
    z-index: 40;
}
.tabs {
    gap: 2px;
    padding: var(--sp-3) var(--sp-5);
}
.tab {
    padding: 8px 15px;
    border-radius: var(--radius-full);
    border-bottom: none !important;
    margin-bottom: 0;
    color: var(--gray-600);
    transition: color 0.2s var(--ease), background 0.2s var(--ease);
}
.tab:hover { color: var(--gray-900); background: rgba(0,0,0,0.04); }
.tab.active {
    color: #fff;
    background: var(--primary);
    box-shadow: 0 2px 8px rgba(0, 113, 227, 0.3);
}
.tab.active:hover { color: #fff; background: var(--primary-hover); }

/* ---- Cartes ---- */
.page-main { padding-top: var(--sp-4); }
.container {
    border: 1px solid var(--border);
    border-radius: var(--radius-lg);
    box-shadow: var(--shadow-sm);
    padding: var(--sp-8);
}
.section-title {
    font-size: 21px;
    font-weight: 650;
    letter-spacing: -0.02em;
    color: var(--gray-900);
}
.subsection {
    border: 1px solid var(--border);
    border-radius: var(--radius);
    background: var(--gray-50);
    padding: var(--sp-5);
}
.subsection h4, .subsection-header h4 {
    font-weight: 600;
    letter-spacing: -0.01em;
}

/* ---- Boutons : remplissage plein, pression tactile ---- */
.btn-create, .btn-wg, .btn-regen, .btn-submit, .btn-sync, .btn-assign {
    border-radius: var(--radius-full);
    font-weight: 550;
    letter-spacing: -0.01em;
    box-shadow: 0 1px 2px rgba(0,0,0,0.06);
    transition: transform 0.12s var(--ease), background 0.2s var(--ease), box-shadow 0.2s var(--ease);
}
.btn-create:hover, .btn-wg:hover, .btn-regen:hover, .btn-submit:hover,
.btn-sync:hover, .btn-assign:hover { transform: translateY(-1px); box-shadow: var(--shadow-sm); }
.btn-create:active, .btn-wg:active, .btn-regen:active, .btn-submit:active,
.btn-sync:active, .btn-assign:active { transform: scale(0.98); }

.btn-sync {
    background: var(--gray-900);
    color: #fff;
    border-color: var(--gray-900);
}
.btn-sync:hover { background: #2b2b2e; }

.btn-small, .btn-select-all, .btn-inline {
    border-radius: var(--radius-full);
    transition: transform 0.12s var(--ease), background 0.2s var(--ease);
}
.btn-small:active, .btn-select-all:active { transform: scale(0.97); }

/* ---- Messages / badges : plus doux ---- */
.message { border-radius: var(--radius); }
.badge { border-radius: var(--radius-full); font-weight: 550; letter-spacing: 0; }

/* ---- Champs : focus bleu diffus ---- */
input[type="text"], input[type="search"], input[type="date"], input[type="number"],
input[type="password"], select, textarea {
    border-radius: var(--radius-sm);
    transition: border-color 0.18s var(--ease), box-shadow 0.18s var(--ease);
}
input:focus, select:focus, textarea:focus { box-shadow: var(--ring); }

/* ---- Vue d'ensemble : tuiles aerees ---- */
.overview-bar {
    background: var(--surface);
    border: 1px solid var(--border);
    border-radius: var(--radius-lg);
    box-shadow: var(--shadow-xs);
}

/* ---- Bulles d'aide : verre depoli ---- */
.help-badge {
    border-color: transparent;
    background: var(--gray-100);
    color: var(--gray-500);
    transition: background 0.18s var(--ease), color 0.18s var(--ease);
}
.help-badge:hover, .help-badge[aria-expanded="true"] { background: var(--primary); color: #fff; }
.help-pop {
    border-radius: 16px;
    box-shadow: 0 16px 48px rgba(0, 0, 0, 0.16);
    border-color: var(--border);
}

/* Petit "?" inline dans les indices */
.hint-help-mark {
    display: inline-flex;
    align-items: center;
    justify-content: center;
    width: 16px; height: 16px;
    border-radius: 50%;
    background: var(--primary-soft);
    color: var(--primary);
    font-size: 11px;
    font-weight: 700;
    vertical-align: -2px;
}

/* ---- Bloc equipements : coherence avec le reste ---- */
.dev-picker-body { border-radius: var(--radius); border: 1px solid var(--border); }
.dev-block-head { background: rgba(0,0,0,0.02); }
.dev-block-head:hover { background: rgba(0,0,0,0.045); }

/* ---- Voile de chargement : verre depoli ---- */
.loading-overlay { background: rgba(245, 245, 247, 0.6); backdrop-filter: saturate(180%) blur(8px); }
.loading-box { border-radius: 18px; box-shadow: 0 24px 60px rgba(0,0,0,0.2); }
.ajax-beacon { border-radius: var(--radius-full); backdrop-filter: saturate(180%) blur(14px); background: rgba(255,255,255,0.85); }

/* ---- Transitions douces globales sur les elements interactifs ---- */
.tab, .btn-create, .btn-wg, .btn-regen, .btn-submit, .btn-sync, .btn-assign,
.help-badge, .logout-btn, .assoc-item, .peer-card, .dev-block-head {
    transition-timing-function: var(--ease);
}

/* Respecte la preference de mouvement reduit */
@media (prefers-reduced-motion: reduce) {
    *, *::before, *::after { transition-duration: 0.01ms !important; }
}

/* ===== Page de gestion des acces (admin_users.html) ===== */

/* Formulaire de creation : grille fluide, une colonne par champ */
.access-form-grid {
    display: grid;
    grid-template-columns: repeat(auto-fit, minmax(220px, 1fr));
    gap: var(--sp-3) var(--sp-4);
    margin-bottom: var(--sp-4);
}
.access-form-grid .form-group { margin-bottom: 0; }

/* Tableau des comptes : editable en ligne, defilement horizontal si besoin */
.table-scroll { overflow-x: auto; }
.access-table { width: 100%; }
.access-table th { white-space: nowrap; }
.access-table td { vertical-align: middle; }
/* .input-inline est defini en `width: 120px !important` (renommage en ligne) :
   dans un tableau editable, cela fige tous les champs a la meme largeur, e-mail
   compris. Ici ils remplissent leur colonne. */
.access-table .input-inline,
.access-table select.input-inline {
    width: 100% !important;
    min-width: 92px;
    box-sizing: border-box;
}
.access-table .input-wide { min-width: 168px; }
.cell-identity { min-width: 150px; }
.cell-identity .input-inline { margin-bottom: 3px; }
.cell-center  { text-align: center; }
.cell-muted   { color: var(--gray-500); font-size: 12px; white-space: nowrap; }
.cell-actions { white-space: nowrap; display: flex; gap: 6px; align-items: center; }

/* Peers rattachés : la liste des noms plutôt qu'un compteur, pour vérifier d'un
   coup d'œil que le base_name de la fiche correspond à des peers réels. */
.cell-peers { min-width: 84px; max-width: 260px; }
.peer-badges { display: flex; flex-wrap: wrap; gap: 4px; }
.peer-badges .badge { font-size: 11px; }

/* Compte desactive : la ligne recule visuellement sans devenir illisible */
.row-inactive { opacity: 0.55; }
.row-inactive td { background: rgba(0, 0, 0, 0.015); }

/* Adresse de remplissage (@import.local) : signalee, car elle bloque le SSO */
.input-warn { border-color: #f59e0b; background: #fffbeb; }
.field-hint-warn { color: #b45309; display: block; margin-top: 2px; }

/* Pastille de niveau d'acces */
.badge-role {
    background: var(--primary-soft, #e0e7ff);
    color: var(--primary, #4338ca);
    text-transform: lowercase;
}
.badge-role-admin { background: #fee2e2; color: #b91c1c; }

/* Identite Entra ID rappelee a cote de chaque utilisateur WireGuard */
.wg-user-identity {
    font-size: 12px;
    color: var(--gray-500);
    white-space: nowrap;
    overflow: hidden;
    text-overflow: ellipsis;
    max-width: 340px;
}
.wg-user-identity-missing { color: #b45309; }

/* ===== Bloc « Titulaire du compte » (création d'un peer WireGuard) =====
   Encadré à part dans le formulaire : c'est l'endroit qui relie un compte du
   tenant Entra ID à ses peers, et la bordure de gauche change de couleur selon
   l'état détecté (nouvel utilisateur, connu, identité incomplète). */
.identity-block {
    padding: var(--sp-3) var(--sp-4);
    background: var(--gray-25, #fcfcfd);
    border: 1px solid var(--border);
    border-left: 3px solid var(--gray-300);
    border-radius: var(--radius-sm);
    transition: border-color 0.15s, background 0.15s;
}
.identity-block-new   { border-left-color: var(--primary); }
.identity-block-known { border-left-color: var(--success); background: var(--success-soft); }
.identity-block-warn  { border-left-color: var(--warning); background: var(--warning-soft); }

.identity-head {
    display: flex;
    align-items: baseline;
    flex-wrap: wrap;
    gap: var(--sp-2, 8px);
    margin-bottom: var(--sp-3);
}
.identity-title { font-weight: 600; font-size: 14px; color: var(--gray-800); }
.identity-sub   { font-size: 12px; color: var(--gray-500); }

/* Pastille d'etat, poussee a droite */
.identity-state {
    margin-left: auto;
    padding: 2px 10px;
    font-size: 11.5px;
    font-weight: 600;
    border-radius: var(--radius-full, 999px);
    background: var(--gray-100);
    color: var(--gray-600);
    white-space: nowrap;
}
.identity-state-new   { background: var(--primary-soft); color: var(--primary-hover); }
.identity-state-known { background: var(--success-soft); color: var(--success-text);
                        border: 1px solid var(--success-border); }
.identity-state-warn  { background: #fff; color: var(--warning-text);
                        border: 1px solid var(--warning-border); }

.identity-grid {
    display: grid;
    grid-template-columns: repeat(auto-fit, minmax(170px, 1fr));
    gap: var(--sp-3, 12px);
}
.identity-field-wide { grid-column: span 2; }
.identity-field label {
    display: block;
    margin-bottom: 4px;
    font-size: 12px;
    font-weight: 550;
    color: var(--gray-600);
}
.identity-req { color: var(--danger); font-weight: 700; }
.identity-field input { width: 100%; box-sizing: border-box; margin: 0; }
/* Champ verrouille : la valeur vient de la fiche existante, on la montre sans
   laisser croire qu'elle se modifie ici (c'est la page Gestion des accès pour ça). */
.identity-field input[readonly] {
    background: var(--gray-100);
    color: var(--gray-600);
    cursor: not-allowed;
}
@media (max-width: 720px) {
    .identity-grid { grid-template-columns: 1fr; }
    .identity-field-wide { grid-column: auto; }
    .identity-state { margin-left: 0; }
}

/* Bouton dont l'action devient destructive selon la saisie (groupe par défaut
   validé sans aucun utilisateur = suppression) */
.btn-danger-intent {
    background: var(--danger);
    border-color: var(--danger-hover);
}
.btn-danger-intent:hover { background: var(--danger-hover); }

/* Utilisateur WireGuard dont l'identité du tenant reste à saisir : l'identifiant
   est mis en ambre — ce n'est pas une erreur, c'est une action en attente. */
.wg-todo-name { font-weight: 600; color: var(--warning-text); white-space: nowrap; }

/* ===== Refus de saisie d'un caractère réservé ('_') ===== */
.input-rejected {
    border-color: var(--danger) !important;
    background: var(--danger-soft);
    animation: shake-reject 0.28s ease;
}
@keyframes shake-reject {
    0%, 100% { transform: translateX(0); }
    25%      { transform: translateX(-3px); }
    75%      { transform: translateX(3px); }
}
.no-underscore-hint {
    display: none;
    margin-top: 3px;
    font-size: 11.5px;
    color: var(--danger-text);
}
.no-underscore-hint.visible { display: block; }
@media (prefers-reduced-motion: reduce) {
    .input-rejected { animation: none; }
}

/* ===== Zone « identité du tenant Microsoft » dans les tableaux =====
   Les colonnes qui portent l'identité Azure sont regroupées visuellement : elles
   se lisent comme un bloc distinct des colonnes WireGuard, ce qui rend évident
   quelle information vient de quel monde. */
.col-azure { background: rgba(0, 120, 212, 0.045); }
.col-azure-first { border-left: 2px solid rgba(0, 120, 212, 0.35); }
.col-azure-last  { border-right: 2px solid rgba(0, 120, 212, 0.35); }
thead .col-azure { background: rgba(0, 120, 212, 0.09); color: #0b5394; }
.row-inactive .col-azure { background: rgba(0, 0, 0, 0.02); }

/* Champ portant une adresse du tenant : monospace léger, l'adresse doit être
   lue caractère par caractère (le rapprochement SSO est une égalité stricte). */
.input-azure {
    font-family: var(--font-mono, ui-monospace, SFMono-Regular, Menlo, monospace);
    font-size: 12.5px;
}
.input-azure:focus { background: #fff; }

/* ===== Carte du compte Microsoft connecté (portail) ===== */
.azure-card {
    display: flex;
    align-items: center;
    gap: var(--sp-4, 16px);
    flex-wrap: wrap;
    padding: var(--sp-3) var(--sp-4);
    margin-bottom: var(--sp-4);
    background: var(--surface);
    border: 1px solid var(--border);
    border-left: 3px solid #0078d4;
    border-radius: var(--radius-sm);
}
.azure-card-logo {
    display: grid;
    grid-template-columns: repeat(2, 11px);
    grid-template-rows: repeat(2, 11px);
    gap: 2px;
    flex: 0 0 auto;
}
.azure-card-body { display: flex; flex-direction: column; gap: 1px; min-width: 0; }
.azure-card-label {
    font-size: 10.5px;
    text-transform: uppercase;
    letter-spacing: 0.05em;
    color: var(--gray-500);
}
.azure-card-name { font-weight: 600; color: var(--gray-800); }
.azure-card-mail {
    font-family: var(--font-mono, ui-monospace, SFMono-Regular, Menlo, monospace);
    font-size: 12.5px;
    color: var(--gray-600);
    overflow-wrap: anywhere;
}
.azure-card-meta {
    display: flex;
    align-items: center;
    gap: var(--sp-2, 8px);
    margin-left: auto;
    flex-wrap: wrap;
}
.azure-card-tag { font-size: 12px; color: var(--gray-600); white-space: nowrap; }
@media (max-width: 640px) {
    .azure-card-meta { margin-left: 0; }
}

/* =========================================================================
   GESTION DES ACCES — mise en page (admin_users.html)
   La page distribue des droits : elle doit se lire comme un tableau de bord,
   pas comme un formulaire. D'ou trois niveaux visuels nets — l'etat global en
   haut (compteurs), la file d'attente WireGuard repliee au milieu, la table
   des comptes en bas.
   ========================================================================= */

/* ---- En-tete de page ---- */
.access-header {
    display: flex;
    align-items: flex-start;
    justify-content: space-between;
    gap: var(--sp-4);
    flex-wrap: wrap;
    margin-bottom: var(--sp-4);
}
.access-title { margin-bottom: var(--sp-2); }
.access-lead {
    max-width: 68ch;
    font-size: 13px;
    color: var(--gray-500);
}

/* ---- Compteurs : une carte par indicateur ---- */
.access-stats {
    display: grid;
    grid-template-columns: repeat(auto-fit, minmax(140px, 1fr));
    gap: var(--sp-3);
    margin-bottom: var(--sp-5);
}
.access-stat {
    display: flex;
    flex-direction: column;
    gap: 2px;
    padding: var(--sp-3) var(--sp-4);
    background: var(--surface);
    border: 1px solid var(--border);
    border-top: 3px solid var(--gray-300);
    border-radius: var(--radius);
    box-shadow: var(--shadow-xs);
}
.access-stat-num {
    font-size: 22px;
    font-weight: 700;
    line-height: 1.1;
    color: var(--gray-800);
    font-variant-numeric: tabular-nums;
}
.access-stat-label {
    font-size: 11.5px;
    text-transform: uppercase;
    letter-spacing: 0.04em;
    color: var(--gray-500);
}
.access-stat-ok { border-top-color: var(--success); }
/* Un indicateur en attente n'est pas une erreur : ambre, jamais rouge. */
.access-stat-warn { border-top-color: var(--warning); background: var(--warning-soft); }
.access-stat-warn .access-stat-num,
.access-stat-warn .access-stat-label { color: var(--warning-text); }

/* ---- Chevron commun a tous les depliants de la page ---- */
.drop-caret {
    display: inline-block;
    flex: 0 0 auto;
    font-size: 10px;
    color: var(--gray-400);
    transition: transform 0.15s var(--ease, ease);
}
details[open] > summary .drop-caret { transform: rotate(90deg); }
/* Le marqueur natif est remplace par notre chevron */
.wg-panel-head::-webkit-details-marker,
.wg-item-head::-webkit-details-marker,
.peer-drop-head::-webkit-details-marker { display: none; }
.wg-panel-head, .wg-item-head, .peer-drop-head { list-style: none; }

/* ---- Menu deroulant « utilisateurs WireGuard a completer » ---- */
.wg-panel { padding: 0; overflow: hidden; }
.wg-panel-head {
    display: flex;
    align-items: center;
    gap: var(--sp-2);
    flex-wrap: wrap;
    padding: var(--sp-3) var(--sp-4);
    cursor: pointer;
    background: var(--warning-soft);
    border-bottom: 1px solid transparent;
    user-select: none;
}
.wg-panel-drop[open] > .wg-panel-head { border-bottom-color: var(--warning-border); }
.wg-panel-head:hover { background: #fef6e0; }
.wg-panel-title { font-weight: 600; color: var(--warning-text); }
.wg-panel-hint { font-size: 12px; color: var(--gray-500); }
.wg-panel-body { padding: var(--sp-4); }
.wg-panel-body .field-hint { margin-bottom: var(--sp-3); }
.wg-filter { width: 100%; margin-bottom: var(--sp-3); }

/* ---- Un utilisateur WireGuard = un depliant qui ouvre son formulaire ---- */
.wg-list { display: flex; flex-direction: column; gap: var(--sp-2); }
.wg-item {
    background: var(--surface);
    border: 1px solid var(--border);
    border-left: 3px solid var(--warning);
    border-radius: var(--radius-sm);
}
.wg-item[open] { box-shadow: var(--shadow-sm); }
.wg-item-head {
    display: flex;
    align-items: center;
    gap: var(--sp-3);
    flex-wrap: wrap;
    padding: var(--sp-2) var(--sp-3);
    cursor: pointer;
    user-select: none;
}
.wg-item-head:hover { background: var(--gray-25); }
.wg-item-count {
    font-size: 12px;
    color: var(--gray-500);
    font-variant-numeric: tabular-nums;
}
.wg-item-state {
    margin-left: auto;
    padding: 1px 9px;
    font-size: 11.5px;
    font-weight: 600;
    border-radius: var(--radius-full);
    background: var(--warning-soft);
    color: var(--warning-text);
    border: 1px solid var(--warning-border);
    white-space: nowrap;
}
.wg-item-body {
    padding: var(--sp-3);
    border-top: 1px solid var(--border);
}
.wg-item-peers {
    display: flex;
    flex-wrap: wrap;
    gap: 4px;
    margin-bottom: var(--sp-3);
}
.wg-item-grid {
    display: grid;
    grid-template-columns: repeat(auto-fit, minmax(170px, 1fr));
    gap: var(--sp-3);
}
.wg-field-wide { grid-column: span 2; }
.wg-field label {
    display: block;
    margin-bottom: 4px;
    font-size: 12px;
    font-weight: 550;
    color: var(--gray-600);
}
/* Le dépliant est un vrai formulaire, pas une cellule de tableau : ses champs
   reprennent la taille normale d'un champ de saisie (.input-inline est defini
   en !important pour les renommages en ligne, on le neutralise ici). */
.wg-field .input-inline {
    width: 100% !important;
    box-sizing: border-box;
    padding: 7px 10px !important;
    font-size: 13px !important;
}
.wg-item-actions {
    display: flex;
    justify-content: flex-end;
    margin-top: var(--sp-3);
}
@media (max-width: 720px) {
    .wg-item-grid { grid-template-columns: 1fr; }
    .wg-field-wide { grid-column: auto; }
    .wg-item-state { margin-left: 0; }
}

/* ---- Peers rattaches : deroulant compact dans la cellule ---- */
.peer-drop { font-size: 12px; }
.peer-drop-head {
    display: inline-flex;
    align-items: center;
    gap: 5px;
    padding: 2px 8px;
    border: 1px solid var(--border);
    border-radius: var(--radius-full);
    background: var(--gray-50);
    color: var(--gray-600);
    cursor: pointer;
    white-space: nowrap;
    user-select: none;
}
.peer-drop-head:hover { background: var(--gray-100); border-color: var(--border-strong); }
.peer-drop[open] .peer-badges { margin-top: 6px; }

/* ---- Ligne verrouillee : l'administrateur declare dans secrets.conf ----
   Rien n'y est cliquable, et cela doit se voir : fond neutre, valeurs en
   texte simple, mention explicite a la place du bouton d'enregistrement. */
.row-locked td { background: var(--gray-50); cursor: default; }
.row-locked .col-azure { background: rgba(0, 120, 212, 0.03); }
.locked-value {
    display: inline-block;
    color: var(--gray-700);
    font-weight: 550;
}
.locked-mono {
    font-family: var(--font-mono);
    font-size: 12.5px;
    font-weight: 400;
    overflow-wrap: anywhere;
}
.locked-muted { color: var(--gray-400); font-weight: 400; }
.lock-tag {
    display: inline-flex;
    align-items: center;
    gap: 5px;
    padding: 2px 9px;
    font-size: 11.5px;
    font-weight: 600;
    color: var(--gray-500);
    background: var(--gray-100);
    border: 1px solid var(--border);
    border-radius: var(--radius-full);
    white-space: nowrap;
    cursor: help;
}

/* Pastille d'etat actif/inactif (colonne non editable de la ligne verrouillee) */
.state-dot {
    display: inline-block;
    width: 9px;
    height: 9px;
    border-radius: 50%;
    background: var(--gray-300);
}
.state-dot-on { background: var(--success); box-shadow: 0 0 0 3px var(--success-soft); }

/* ---- Compteur en pastille (en-tetes de depliants) ---- */
.badge-count {
    background: var(--warning);
    color: #fff;
    font-weight: 700;
    font-size: 11.5px;
    padding: 1px 8px;
    border-radius: var(--radius-full);
}

/* ---- Table des comptes : en-tete qui reste visible au defilement ---- */
.access-table thead th {
    position: sticky;
    top: 0;
    z-index: 2;
    background: var(--gray-50);
}
.access-table thead th.col-azure { background: #e3eefb; }
.access-table tbody tr:hover td { background: var(--gray-25); }
.access-table tbody tr.row-locked:hover td { background: var(--gray-50); }
/* Plafond de hauteur reserve a la table des comptes (l'en-tete colle) */
.access-scroll { max-height: 70vh; overflow: auto; }

/* ---- Message de deconnexion (page de connexion) ---- */
.login-signedout { text-align: left; font-weight: 400; }
.login-other-account {
    display: inline-block;
    margin-top: var(--sp-2);
    font-size: 12.5px;
    color: var(--gray-500);
    text-decoration: underline;
}
.login-other-account:hover { color: var(--primary); }

/* Neuf colonnes tiennent difficilement sur un portable : les cellules de la
   table des acces restent compactes, et le conteneur defile au besoin. */
.access-table td, .access-table th { padding-left: var(--sp-2); padding-right: var(--sp-2); }
.access-table input[type="date"].input-inline { min-width: 128px; }
.access-table .cell-actions { gap: 4px; }

/* La colonne d'actions reste accrochee a droite : le bouton Enregistrer doit
   etre atteignable sans faire defiler la table horizontalement. */
.access-table th:last-child,
.access-table td.cell-actions {
    /* table-cell (et non flex) : la cellule doit garder la hauteur de sa ligne,
       sans quoi l'ancrage a droite la desaligne du reste du tableau. */
    display: table-cell;
    vertical-align: middle;
    white-space: nowrap;
    position: sticky;
    right: 0;
    z-index: 1;
    background: var(--surface);
    box-shadow: -8px 0 8px -8px rgba(15, 23, 42, 0.25);
}
.access-table thead th:last-child { z-index: 3; background: var(--gray-50); }
.access-table td.cell-actions > * { vertical-align: middle; }
.access-table td.cell-actions .inline-form { display: inline-block; margin-left: 4px; }
.access-table tbody tr:hover td.cell-actions { background: var(--gray-25); }
.access-table tbody tr.row-locked td.cell-actions,
.access-table tbody tr.row-locked:hover td.cell-actions { background: var(--gray-50); }

/* Derniere connexion : rappelee sous l'identite plutot que dans une colonne a
   elle seule — la table gagne la place que reclament les champs editables. */
.cell-lastlogin {
    display: block;
    margin-top: 3px;
    font-size: 11px;
    color: var(--gray-400);
    white-space: nowrap;
}

/* Colonne « Validité » : l'état actif et l'échéance des droits, empilés. */
.cell-validity { min-width: 132px; }
.cell-validity .switch { margin-bottom: 5px; }
.validity-state {
    display: flex;
    align-items: center;
    gap: 6px;
    font-size: 12px;
    color: var(--gray-600);
    margin-bottom: 2px;
}
.cell-validity .locked-value { font-size: 12px; }

/* La gestion des accès est une page de tableau : elle respire mal dans la
   largeur de lecture du reste de l'application, ou les colonnes editables
   finissent hors champ. On lui laisse la largeur de l'ecran. */
.page-main-wide { max-width: 1400px; }

/* Colonnes compactees pour que la table entiere tienne sans defilement sur un
   ecran courant : chaque champ garde une largeur utilisable, pas davantage. */
.access-table .input-wide { min-width: 130px; }
.access-table input[type="date"].input-inline { min-width: 116px; }
.cell-validity { min-width: 120px; }
.cell-identity { min-width: 128px; }


/* =========================================================================
   CREATION D'UN UTILISATEUR WIREGUARD — bloc « titulaire »
   L'adresse Microsoft est le point de depart : elle est mise en avant, et ce
   qui en decoule (prenom, nom, identifiant WireGuard, noms des peers) se lit
   dans l'ordre ou on le remplit.
   ========================================================================= */

/* Etiquette « on part de là » / « proposé d'après l'adresse » */
.field-lead {
    display: inline-block;
    margin-left: 6px;
    padding: 1px 7px;
    font-size: 10.5px;
    font-weight: 600;
    text-transform: none;
    letter-spacing: 0;
    border-radius: var(--radius-full);
    background: var(--primary-soft);
    color: var(--primary-hover);
    vertical-align: 1px;
}

/* Identifiant WireGuard : sur sa propre ligne, separe des champs d'identite */
.identity-name-row {
    margin-bottom: var(--sp-3);
    padding-bottom: var(--sp-3);
    border-bottom: 1px dashed var(--border);
}
.identity-name-row .identity-field-wide { grid-column: auto; }
.identity-name-row .field-hint { margin-top: 4px; }

/* Recapitulatif : ce qui sera reellement cree sur le routeur */
.identity-recap {
    display: flex;
    align-items: baseline;
    gap: var(--sp-2);
    flex-wrap: wrap;
    margin-top: var(--sp-3);
    padding: var(--sp-2) var(--sp-3);
    background: var(--surface);
    border: 1px solid var(--border);
    border-radius: var(--radius-sm);
}
.identity-recap-label {
    font-size: 11px;
    text-transform: uppercase;
    letter-spacing: 0.04em;
    color: var(--gray-500);
}
.identity-recap strong { font-family: var(--font-mono); font-size: 13px; }

/* =========================================================================
   CHAMPS DE DROITS (page Gestion des accès)
   Le niveau d'acces et la validite decident de ce qu'une personne peut faire :
   ils doivent se lire d'un coup d'oeil dans la ligne, pas se fondre dans les
   autres champs.
   ========================================================================= */
.role-select {
    font-weight: 600;
    border-radius: var(--radius-full);
    padding: 5px 10px;
    border: 1px solid var(--border-strong);
    background-color: var(--gray-100);
    color: var(--gray-700);
    cursor: pointer;
}
.role-select[data-role="full"] {
    background-color: var(--primary-soft);
    border-color: var(--primary-border);
    color: var(--primary-hover);
}
.role-select[data-role="readonly"] {
    background-color: var(--gray-100);
    border-color: var(--border-strong);
    color: var(--gray-600);
}
.role-select:hover { border-color: var(--primary); }
/* « Lecture seule » doit tenir en entier : un intitule de droits tronque ne se
   devine pas. La place vient des colonnes voisines, resserrees d'autant. */
.access-table select.role-select { min-width: 132px; font-size: 12.5px; padding: 5px 8px; }
.wg-field select.role-select { width: 100% !important; }

/* Interrupteur « actif » : un etat, pas une case a cocher perdue au milieu */
.switch {
    display: inline-flex;
    align-items: center;
    gap: 7px;
    cursor: pointer;
    user-select: none;
    font-size: 12px;
    color: var(--gray-600);
}
.switch input { position: absolute; opacity: 0; width: 0; height: 0; }
.switch-track {
    position: relative;
    width: 32px;
    height: 18px;
    flex: 0 0 auto;
    border-radius: var(--radius-full);
    background: var(--gray-300);
    transition: background 0.15s var(--ease, ease);
}
.switch-thumb {
    position: absolute;
    top: 2px;
    left: 2px;
    width: 14px;
    height: 14px;
    border-radius: 50%;
    background: #fff;
    box-shadow: var(--shadow-xs);
    transition: transform 0.15s var(--ease, ease);
}
.switch input:checked + .switch-track { background: var(--success); }
.switch input:checked + .switch-track .switch-thumb { transform: translateX(14px); }
.switch input:focus-visible + .switch-track { box-shadow: var(--ring); }
.switch input:checked ~ .switch-label { color: var(--success-text); font-weight: 600; }

/* Fin de droits : discrete tant qu'elle est vide, marquee des qu'elle existe */
.date-limit { font-size: 12px; }
.date-limit:not([value=""]) { border-color: var(--warning-border); background: var(--warning-soft); }

/* Fin de droits : le mode puis la date, empiles dans la cellule Validité */
.validity-limit { display: flex; flex-direction: column; gap: 4px; }
.validity-mode { font-size: 12px; }
.access-table select.validity-mode { min-width: 118px; }

/* Liste consultative des utilisateurs WireGuard existants (création d'un peer) */
.wg-existing { margin-top: var(--sp-3); }
.wg-existing-head {
    display: flex;
    align-items: center;
    gap: var(--sp-2);
    flex-wrap: wrap;
    padding: 6px 0;
    font-size: 12.5px;
    font-weight: 600;
    color: var(--gray-600);
    cursor: pointer;
    list-style: none;
    user-select: none;
}
.wg-existing-head::-webkit-details-marker { display: none; }
.wg-existing-hint { font-weight: 400; color: var(--gray-400); }
.badge-count-soft {
    background: var(--gray-200);
    color: var(--gray-700);
    font-weight: 700;
    font-size: 11px;
    padding: 1px 7px;
    border-radius: var(--radius-full);
}
.wg-existing-list {
    display: flex;
    flex-wrap: wrap;
    gap: var(--sp-2);
    padding: var(--sp-2) 0 2px;
}
.wg-existing-item {
    display: inline-flex;
    align-items: baseline;
    gap: 6px;
    padding: 3px 10px;
    background: var(--surface);
    border: 1px solid var(--border);
    border-radius: var(--radius-full);
    font-size: 12px;
}
.wg-existing-item strong { font-family: var(--font-mono); font-size: 12px; }
.wg-existing-mail { color: var(--gray-500); }
