/* bitborg theme for Forgejo — served at /assets/css/bitborg.css and loaded via the custom
 * header hook (templates/custom/header.tmpl). Recolours Forgejo's built-in themes to the
 * gitborg palette so they cohere with gitborg-web and the Kanidm UI:
 *   - light  → soft cool-white ground, navy ink, blue (sky) primary/links
 *   - dark   → navy ground, soft-white ink, yellow (sun) primary/links
 * The Swedish-flag palette is injected by overriding Forgejo's semantic CSS variables only,
 * scoped to the active theme via <html data-theme>. forgejo-auto follows prefers-color-scheme
 * (light by default, dark when the OS prefers it), exactly like gitborg-web.
 *
 * Additive and upgrade-safe: we only redefine documented --color-* variables; Forgejo's
 * neutral surfaces/borders ride along. If a variable is renamed upstream the rule no-ops.
 * The colour-blind theme variants (…-tritanopia, …-deuteranopia-protanopia) and the gitea-*
 * themes are intentionally left untouched so their tuned palettes are preserved. */

/* ===== gitborg theme — LIGHT (forgejo-light, and forgejo-auto by default) ===== */
:root[data-theme="forgejo-light"],
:root[data-theme="forgejo-auto"] {
  --color-primary: #006aa7;
  --color-primary-contrast: #ffffff;
  --color-primary-dark-1: #005e95;
  --color-primary-dark-2: #00537f;
  --color-primary-dark-3: #00496f;
  --color-primary-dark-4: #003f60;
  --color-primary-dark-5: #003251;
  --color-primary-dark-6: #002868;
  --color-primary-dark-7: #001f50;
  --color-primary-light-1: #1a82c0;
  --color-primary-light-2: #3d97cf;
  --color-primary-light-3: #66aedb;
  --color-primary-light-4: #93c6e6;
  --color-primary-light-5: #c0ddf1;
  --color-primary-light-6: #dcebf8;
  --color-primary-light-7: #eef5fb;
  --color-primary-hover: var(--color-primary-dark-2);
  --color-primary-active: var(--color-primary-dark-4);
  --color-accent: #00578a;
  --color-body: #f6f8fb;
  --color-box-body: #ffffff;
  --color-box-body-highlight: #eef2f7;
  --color-box-header: #eef1f5;
  --color-header-wrapper: #eef1f5;
  --color-header-wrapper-transparent: #eef1f500;
  --color-footer: #eef1f5;
  --color-nav-bg: #eef1f5;
  --color-nav-hover-bg: #e1e7ef;
  --color-secondary: #d6dee8;
  --color-secondary-bg: #eef1f5;
  --color-text: #001144;
  --color-text-light: #33425c;
  --color-text-light-1: #3f4f6b;
  --color-text-light-2: #4a5a6a;
  --color-text-light-3: #66758a;
  --color-input-background: #ffffff;
  --color-input-border: #7d8ba0;
  --color-input-border-hover: #6f7e94;
  --color-input-text: #001144;
  --color-markup-code-block: #eef2f7;
  --color-markup-code-inline: #e7edf4;
  --color-primary-alpha-10: #006aa719;
  --color-primary-alpha-20: #006aa733;
  --color-primary-alpha-30: #006aa74b;
  --color-primary-alpha-40: #006aa766;
  --color-primary-alpha-50: #006aa780;
  --color-primary-alpha-60: #006aa799;
  --color-primary-alpha-70: #006aa7b3;
  --color-primary-alpha-80: #006aa7cc;
  --color-primary-alpha-90: #006aa7e1;
}

/* ===== gitborg theme — DARK (forgejo-dark, and forgejo-auto when the OS prefers dark) ===== */
:root[data-theme="forgejo-dark"] {
  --color-primary: #fecc00;
  --color-primary-contrast: #001144;
  --color-primary-dark-1: #ffd633;
  --color-primary-dark-2: #ffdf5c;
  --color-primary-dark-3: #ffe680;
  --color-primary-dark-4: #ffeea3;
  --color-primary-dark-5: #fff3c2;
  --color-primary-dark-6: #fff8db;
  --color-primary-dark-7: #fffbe9;
  --color-primary-light-1: #e6b800;
  --color-primary-light-2: #cca300;
  --color-primary-light-3: #997a00;
  --color-primary-light-4: #665100;
  --color-primary-light-5: #4a3b00;
  --color-primary-light-6: #332900;
  --color-primary-light-7: #241d00;
  --color-primary-hover: var(--color-primary-dark-1);
  --color-primary-active: var(--color-primary-dark-2);
  --color-accent: #fecc00;
  --color-body: #001144;
  --color-box-body: #04173b;
  --color-box-body-highlight: #0a2150;
  --color-box-header: #061a45;
  --color-header-wrapper: #000d33;
  --color-header-wrapper-transparent: #000d3300;
  --color-footer: #000a29;
  --color-nav-bg: #000d33;
  --color-nav-hover-bg: #0a2150;
  --color-secondary: #1f3a66;
  --color-secondary-bg: #04173b;
  --color-text: #e9eef6;
  --color-text-light: #b9c6da;
  --color-text-light-1: #aebed4;
  --color-text-light-2: #9fb0c8;
  --color-text-light-3: #8295b0;
  --color-input-background: #002868;
  --color-input-border: #4a7fb5;
  --color-input-border-hover: #5a8fc0;
  --color-input-text: #e9eef6;
  --color-markup-code-block: #04173b;
  --color-markup-code-inline: #061a45;
  --color-primary-alpha-10: #fecc0019;
  --color-primary-alpha-20: #fecc0033;
  --color-primary-alpha-30: #fecc004b;
  --color-primary-alpha-40: #fecc0066;
  --color-primary-alpha-50: #fecc0080;
  --color-primary-alpha-60: #fecc0099;
  --color-primary-alpha-70: #fecc00b3;
  --color-primary-alpha-80: #fecc00cc;
  --color-primary-alpha-90: #fecc00e1;
}

@media (prefers-color-scheme: dark) {
  :root[data-theme="forgejo-auto"] {
    --color-primary: #fecc00;
    --color-primary-contrast: #001144;
    --color-primary-dark-1: #ffd633;
    --color-primary-dark-2: #ffdf5c;
    --color-primary-dark-3: #ffe680;
    --color-primary-dark-4: #ffeea3;
    --color-primary-dark-5: #fff3c2;
    --color-primary-dark-6: #fff8db;
    --color-primary-dark-7: #fffbe9;
    --color-primary-light-1: #e6b800;
    --color-primary-light-2: #cca300;
    --color-primary-light-3: #997a00;
    --color-primary-light-4: #665100;
    --color-primary-light-5: #4a3b00;
    --color-primary-light-6: #332900;
    --color-primary-light-7: #241d00;
    --color-primary-hover: var(--color-primary-dark-1);
    --color-primary-active: var(--color-primary-dark-2);
    --color-accent: #fecc00;
    --color-body: #001144;
    --color-box-body: #04173b;
    --color-box-body-highlight: #0a2150;
    --color-box-header: #061a45;
    --color-header-wrapper: #000d33;
    --color-header-wrapper-transparent: #000d3300;
    --color-footer: #000a29;
    --color-nav-bg: #000d33;
    --color-nav-hover-bg: #0a2150;
    --color-secondary: #1f3a66;
    --color-secondary-bg: #04173b;
    --color-text: #e9eef6;
    --color-text-light: #b9c6da;
    --color-text-light-1: #aebed4;
    --color-text-light-2: #9fb0c8;
    --color-text-light-3: #8295b0;
    --color-input-background: #002868;
    --color-input-border: #4a7fb5;
    --color-input-border-hover: #5a8fc0;
    --color-input-text: #e9eef6;
    --color-markup-code-block: #04173b;
    --color-markup-code-inline: #061a45;
    --color-primary-alpha-10: #fecc0019;
    --color-primary-alpha-20: #fecc0033;
    --color-primary-alpha-30: #fecc004b;
    --color-primary-alpha-40: #fecc0066;
    --color-primary-alpha-50: #fecc0080;
    --color-primary-alpha-60: #fecc0099;
    --color-primary-alpha-70: #fecc00b3;
    --color-primary-alpha-80: #fecc00cc;
    --color-primary-alpha-90: #fecc00e1;
  }
}

/* ===== Identity concealment (ADR 0038) =====================================
 * Kanidm owns the display name and the email address; the portal is where they
 * are edited; the reconciler pushes them onto the Forgejo account. Forgejo has
 * NO config switch for these two fields — [admin].EXTERNAL_USER_DISABLE_FEATURES
 * accepts only deletion / manage_ssh_keys / manage_gpg_keys / manage_password —
 * so the fields are concealed here and enforced by the reconciler.
 *
 * This is concealment, NOT enforcement: the POST endpoints still accept a write,
 * and the reconciler is what makes the Kanidm value true again (within one cycle).
 *
 * Selectors are matched against Forgejo 16.0.2 markup (templates/user/settings/
 * profile.tmpl and account.tmpl); still matching on 16.0.3 (re-verified 2026-08-31
 * via computed style: the concealed controls resolve to display:none, the passkey
 * naming row stays display:flex). Re-verified on 16.0.2 on 2026-08-19 by toggling this
 * stylesheet off and confirming each control becomes visible, which is what
 * distinguishes a working selector from one matching nothing. They are NOT a
 * supported API and can break on any upgrade — the settings-concealment health
 * check is what stops that failing silently. Keep the two in step (ADR 0028
 * upgrade cadence).
 *
 * No guidance text is injected here on purpose: CSS `content` cannot be localised
 * and Forgejo renders in both sv-SE and en. The "where do I change this" pointer
 * lives in the portal and the docs, which are properly bilingual. */

/* /user/settings — the Full Name field (a bare <label> wrapping the input). */
.user-setting-content label:has(input[name="full_name"]) {
  display: none;
}

/* /user/settings/account — the "Set as primary" control on each email row.
 * Deliberately narrow: adding, activating and deleting ADDITIONAL addresses stays
 * available, because those are commit attribution rather than identity, and
 * removing them would break attributing historic commits. Only the choice of
 * PRIMARY address is withdrawn — that is the one the reconciler owns.
 * The activation form shares this action, so match on the _method value. */
.user-setting-content
  .right.floated.content:has(input[name="_method"][value="PRIMARY"]) {
  display: none;
}
