/* =====================================================================
   ko-auth.css — KeurigOnline auth screens (login, 2FA, wachtwoord vergeten,
   nieuw wachtwoord, klantnummer vergeten, registreren, profiel aanvullen).
   Ported 1:1 from the rebuild (drs dev):
     src/System/Adapter/Web/Layouts/auth.twig            (container + base)
     src/System/Adapter/Web/Components/Auth/AuthCard/AuthCard.css
     src/System/Adapter/Web/Components/Base/Flash/Flash.css
     src/System/Adapter/Web/Pages/Auth/ProfileCompletion/ProfileCompletion.css
   Standalone: needs NO Bootstrap, NO jQuery, NO Font Awesome.
   Place at public_html/template/css/ko-auth.css.
   Fonts: Inter from /template/fonts/ (already there).
   ===================================================================== */

/* ---------- 1. Container, tokens, base form, buttons, password input (Layouts/auth.twig) ---------- */
/* Fonts: Inter, zelf-gehost in /template/fonts/ (400 en 700; 500/600 benadert de browser). */
@font-face { font-family: 'Inter'; font-weight: 400; font-style: normal; font-display: swap; src: url('/template/fonts/Inter-Regular.woff2') format('woff2'); }
@font-face { font-family: 'Inter'; font-weight: 700; font-style: normal; font-display: swap; src: url('/template/fonts/Inter-Bold.woff2') format('woff2'); }

/* Reboot shim — the observable subset of Bootstrap 5.3.2's reboot that the
   legacy page pulled from the CDN (login.php:48). Only what the auth markup
   actually relies on: border-box sizing and a zeroed body margin. */
*, *::before, *::after { box-sizing: border-box; }
body { margin: 0; -webkit-text-size-adjust: 100%; }

/* Body font — legacy login.php:60-64 verbatim */
body {
    font-family: 'Inter', -apple-system, BlinkMacSystemFont, 'Segoe UI', Roboto, sans-serif;
}

/* Component-layout body + wrapper — legacy login.php:91-115 verbatim */
body {
    background-color: #F8FCF6 !important;
    min-height: 100vh;
}
.pk-component-wrapper {
    min-height: 100vh;
    display: flex;
    flex-direction: column;
}
.pk-footer {
    margin-top: auto;
    padding: 2rem 1rem;
    text-align: center;
    font-size: 0.875rem;
    color: #6B7280;
}
.pk-footer a {
    color: #3B82F6;
    text-decoration: none;
}
.pk-footer a:hover {
    text-decoration: underline;
}

/* ============================================
   Design tokens + accessibility —
   Components/Auth/Base/AuthAccessibility.php:18-134 verbatim
   ============================================ */
:root {
  --pk-bg-primary: #FFFFFF;
  --pk-bg-secondary: #F9FAFB;
  --pk-bg-tertiary: #F3F4F6;
  --pk-text-primary: #111827;
  --pk-text-secondary: #6B7280;
  --pk-text-tertiary: #9CA3AF;
  --pk-text-inverse: #FFFFFF;
  --pk-border-light: #E5E7EB;
  --pk-border-medium: #D1D5DB;
  --pk-border-dark: #9CA3AF;
  --pk-orange: #FF6B35;
  --pk-orange-hover: #E85A2B;
  --pk-orange-light: #FFF5F2;
  --pk-blue: #3B82F6;
  --pk-blue-hover: #2563EB;
  --pk-red: #DC2626;
  --pk-red-light: #FEE2E2;
  --pk-green: #10B981;
  --pk-green-light: #D1FAE5;
  /* Primary button = KeurigOranje everywhere (Pablo 2026-07-27) — auth
     screens match the app's .c-btn--primary orange, not the old near-black. */
  --pk-btn-primary-bg: #F26522;
  --pk-btn-primary-hover: #D9500F;
  --pk-btn-secondary-bg: #FFFFFF;
  --pk-btn-secondary-border: #D1D5DB;
  --pk-btn-tertiary-bg: #F3F4F6;
  --pk-space-1: 0.25rem;
  --pk-space-2: 0.5rem;
  --pk-space-3: 0.75rem;
  --pk-space-4: 1rem;
  --pk-space-5: 1.5rem;
  --pk-space-6: 2rem;
  --pk-space-8: 3rem;
  --pk-radius-md: 0.625rem;
  --pk-radius-lg: 0.75rem;
  --pk-font-xs: 0.75rem;
  --pk-font-sm: 0.875rem;
  --pk-font-base: 1rem;
  --pk-font-lg: 1.125rem;
  --pk-font-xl: 1.25rem;
  --pk-font-2xl: 1.5rem;
  --pk-weight-medium: 500;
  --pk-weight-semibold: 600;
  --pk-weight-bold: 700;
  --pk-shadow-focus: 0 0 0 3px rgba(255, 107, 53, 0.1);
  --pk-transition-fast: 150ms ease;
  --pk-transition-base: 200ms ease;
  --pk-z-dropdown: 50;
  --pk-z-modal: 100;
  --pk-z-tooltip: 200;
}
.pk-sr-only {
  position: absolute;
  width: 1px;
  height: 1px;
  padding: 0;
  margin: -1px;
  overflow: hidden;
  clip: rect(0, 0, 0, 0);
  white-space: nowrap;
  border-width: 0;
}
*:focus-visible {
  outline: 2px solid var(--pk-orange, #FF6B35);
  outline-offset: 2px;
}
*:focus:not(:focus-visible) {
  outline: none;
}
.pk-skip-to-main {
  position: absolute;
  top: -40px;
  left: 0;
  background: var(--pk-btn-primary-bg, #111827);
  color: var(--pk-text-inverse, #FFFFFF);
  padding: 8px 16px;
  text-decoration: none;
  z-index: 1000;
}
.pk-skip-to-main:focus {
  top: 0;
}
@media (prefers-contrast: high) {
  :root {
    --pk-border-medium: #000000;
    --pk-text-secondary: #000000;
  }
}
@media (prefers-reduced-motion: reduce) {
  *,
  *::before,
  *::after {
    animation-duration: 0.01ms !important;
    animation-iteration-count: 1 !important;
    transition-duration: 0.01ms !important;
  }
}

/* ============================================
   AUTH CONTAINER LAYOUT —
   Components/Auth/Base/AuthContainer.php:44-353 verbatim
   ============================================ */
.pk-auth-wrapper {
  height: 100vh;
  height: 100dvh;
  display: flex;
  flex-direction: column;
  overflow-x: hidden;
  overflow-y: hidden;
  overscroll-behavior: contain;
}
.pk-auth-header {
  width: 100%;
  padding: var(--pk-space-3, 0.75rem) var(--pk-space-4, 1rem);
  box-sizing: border-box;
  display: flex;
  align-items: center;
  justify-content: space-between;
}
@media (min-width: 640px) {
  .pk-auth-header {
    padding: var(--pk-space-4, 1rem) var(--pk-space-6, 2rem);
  }
}
.pk-auth-logo {
  display: inline-flex;
  align-items: center;
  gap: var(--pk-space-3, 0.75rem);
  font-size: var(--pk-font-2xl, 1.5rem);
  font-weight: var(--pk-weight-bold, 700);
  color: var(--pk-text-primary, #111827);
  text-decoration: none;
}
.pk-auth-logo:hover {
  opacity: 0.9;
}
.pk-auth-logo img {
  height: 32px;
  width: auto;
}
.pk-auth-container {
  flex: 1;
  width: 100%;
  max-width: 100%;
  margin: 0 auto;
  padding: var(--pk-space-8, 3rem) var(--pk-space-4, 1rem) var(--pk-space-6, 2rem);
  display: flex;
  flex-direction: column;
  align-items: center;
  box-sizing: border-box;
  min-height: 0;
  overflow-y: auto;
}
@media (min-width: 641px) {
  .pk-auth-header {
    max-width: none;
    margin: 0;
    padding: var(--pk-space-6, 2rem) var(--pk-space-6, 2rem);
  }
  .pk-auth-container {
    flex: 1;
    justify-content: center;
    align-items: center;
    padding: var(--pk-space-8, 3rem) var(--pk-space-4, 1rem);
    max-width: none;
    background: transparent !important;
    border: none !important;
    border-radius: 0;
    max-height: none;
    min-height: 0;
    overflow: visible;
  }
  .pk-auth-content {
    width: 420px !important;
    max-width: 420px !important;
    min-width: 0;
    flex: 0 0 auto;
    display: flex;
    flex-direction: column;
    align-items: stretch;
    justify-content: center;
    gap: var(--pk-space-6, 2rem);
  }
  .pk-auth-content > *,
  .pk-auth-content .pk-login-form,
  .pk-auth-content .pk-auth-form,
  .pk-auth-content form {
    width: 100% !important;
    max-width: 100% !important;
    box-sizing: border-box;
  }
}
@media (max-width: 640px) {
  .pk-auth-logo {
    font-size: var(--pk-font-xl, 1.25rem);
  }
  .pk-auth-logo img {
    height: 24px;
  }
}
.pk-auth-content {
  width: 100%;
  display: flex;
  flex-direction: column;
  min-height: 0;
  flex: 1;
}
.pk-auth-footer {
  width: 100%;
  padding: var(--pk-space-6, 2rem) var(--pk-space-4, 1rem);
  text-align: center;
  font-size: var(--pk-font-sm, 0.875rem);
  color: var(--pk-text-secondary, #6B7280);
  flex-shrink: 0;
  box-sizing: border-box;
}
@media (max-width: 640px) {
  .pk-auth-footer {
    display: none;
  }
}
.pk-auth-footer p {
  margin: 0;
}
.pk-auth-footer a {
  color: var(--pk-text-secondary, #6B7280);
  text-decoration: none;
  transition: color var(--pk-transition-fast, 150ms ease), text-decoration var(--pk-transition-fast, 150ms ease);
}
.pk-auth-footer a:hover {
  color: var(--pk-text-primary, #111827);
  text-decoration: underline;
}
@media (max-width: 640px) {
  .pk-auth-container {
    justify-content: flex-end;
    padding-bottom: calc(var(--pk-space-6, 2rem) + env(safe-area-inset-bottom));
  }
  .pk-auth-content {
    flex: 0 0 auto !important;
  }
  .pk-auth-form,
  .pk-totp-form,
  .pk-login-form-wrapper,
  .pk-login-form,
  .pk-password-change-form,
  .pk-password-reset-form {
    display: flex;
    flex-direction: column;
    flex: 1;
  }
  .pk-auth-form > button[type="submit"]:last-child,
  .pk-login-form > button[type="submit"]:last-child,
  .pk-password-change-form > button[type="submit"]:last-child,
  .pk-password-reset-form > button[type="submit"]:last-child,
  .pk-auth-form > .pk-btn:last-child,
  .pk-login-form > .pk-btn:last-child,
  .pk-password-change-form > .pk-btn:last-child,
  .pk-password-reset-form > .pk-btn:last-child {
    margin-top: auto;
    padding-bottom: env(safe-area-inset-bottom);
  }
}

/* ============================================
   Base form styles —
   Components/Auth/Base/AuthFormBase.php:253-481 verbatim
   (the :root token block it repeats is emitted once above)
   ============================================ */
.pk-form-group {
  margin-bottom: var(--pk-space-4);
}
.pk-form-label {
  display: block;
  font-size: var(--pk-font-sm);
  font-weight: var(--pk-weight-medium);
  color: var(--pk-text-primary);
  margin-bottom: var(--pk-space-2);
}
.pk-form-input {
  width: 100%;
  height: 48px;
  padding: 0 var(--pk-space-4);
  border: 1px solid var(--pk-border-medium);
  border-radius: var(--pk-radius-md);
  font-size: var(--pk-font-base);
  font-family: inherit;
  color: var(--pk-text-primary);
  background: var(--pk-bg-primary);
  transition: border-color var(--pk-transition-fast), box-shadow var(--pk-transition-fast);
  box-sizing: border-box;
  -webkit-appearance: none;
  touch-action: manipulation;
}
.pk-form-input::placeholder {
  color: var(--pk-text-tertiary);
}
.pk-form-input:focus {
  outline: none;
  border-color: var(--pk-orange);
  box-shadow: var(--pk-shadow-focus);
}
.pk-form-input:focus-visible {
  outline: none;
  border-color: var(--pk-orange);
  box-shadow: var(--pk-shadow-focus);
}
.pk-form-input.error {
  border-color: var(--pk-red);
}
.pk-form-input:disabled {
  background: var(--pk-bg-tertiary);
  color: var(--pk-text-tertiary);
  cursor: not-allowed;
}
@media (max-width: 640px) {
  .pk-form-input {
    font-size: 16px;
  }
}
.pk-btn {
  display: inline-flex;
  align-items: center;
  justify-content: center;
  gap: var(--pk-space-2);
  height: 48px;
  padding: 0 var(--pk-space-5);
  border: none;
  border-radius: var(--pk-radius-lg);
  font-size: var(--pk-font-base);
  font-weight: var(--pk-weight-medium);
  font-family: inherit;
  cursor: pointer;
  transition: background var(--pk-transition-base), transform var(--pk-transition-base);
  text-decoration: none;
  box-sizing: border-box;
  width: 100%;
  touch-action: manipulation;
  -webkit-tap-highlight-color: transparent;
}
.pk-btn:disabled {
  opacity: 0.5;
  cursor: not-allowed;
}
.pk-btn:focus-visible {
  outline: none;
  box-shadow: var(--pk-shadow-focus);
}
.pk-btn-primary {
  background: var(--pk-btn-primary-bg);
  color: var(--pk-text-inverse);
}
.pk-btn-primary:hover:not(:disabled) {
  background: var(--pk-btn-primary-hover);
}
.pk-btn-primary:active:not(:disabled) {
  transform: scale(0.98);
}
.pk-btn-secondary {
  background: var(--pk-btn-secondary-bg);
  color: var(--pk-text-primary);
  border: 1px solid var(--pk-btn-secondary-border);
}
.pk-btn-secondary:hover:not(:disabled) {
  background: var(--pk-bg-secondary);
  border-color: var(--pk-border-dark);
}
.pk-btn.loading {
  position: relative;
  pointer-events: none;
}
.pk-btn.loading::before {
  content: "";
  width: 16px;
  height: 16px;
  border: 2px solid currentColor;
  border-radius: 50%;
  border-top-color: transparent;
  animation: pk-spin 0.6s linear infinite;
  flex-shrink: 0;
}
@keyframes pk-spin {
  to { transform: rotate(360deg); }
}
.pk-link {
  color: var(--pk-text-secondary, #6B7280);
  text-decoration: none;
  font-size: var(--pk-font-sm);
  transition: color var(--pk-transition-fast), text-decoration var(--pk-transition-fast);
  touch-action: manipulation;
  -webkit-tap-highlight-color: transparent;
}
.pk-link:hover {
  color: var(--pk-text-primary, #111827);
  text-decoration: underline;
}
.pk-link:focus-visible {
  outline: 2px solid var(--pk-orange);
  outline-offset: 2px;
  border-radius: 2px;
}
.pk-form-error {
  font-size: var(--pk-font-xs);
  color: var(--pk-red);
  margin-top: var(--pk-space-1);
  display: none;
}
.pk-form-error.show {
  display: block;
}
.pk-form-helper {
  font-size: var(--pk-font-xs);
  color: var(--pk-text-secondary);
  margin-top: var(--pk-space-1);
}
.pk-divider {
  display: flex;
  align-items: center;
  gap: var(--pk-space-3);
  margin: var(--pk-space-5) 0;
  color: var(--pk-text-tertiary);
  font-size: var(--pk-font-sm);
  text-transform: lowercase;
}
.pk-divider::before,
.pk-divider::after {
  content: "";
  flex: 1;
  height: 1px;
  background: var(--pk-border-light);
}
@media (prefers-reduced-motion: reduce) {
  .pk-btn { transition: none; }
  .pk-btn:active:not(:disabled) { transform: none; }
  .pk-btn.loading::before { animation: none; border-top-color: currentColor; }
}

/* iOS-zoom / desktop input sizing — Components/Auth/Styles/AuthAccessibility.php:119-135 */
@media (max-width: 640px) {
  input,
  textarea,
  select {
    font-size: 16px;
  }
}
@media (min-width: 641px) {
  input:not(.pk-totp-digit),
  textarea,
  select {
    font-size: 14px;
  }
}

/* ============================================
   Shared per-form rules. In legacy each form class repeated the exact same
   header/title/mobile block (IdentifierForm.php:61-111, PasswordStepForm.php:47-147,
   PasswordResetForm.php:34-107, PasswordChangeForm.php:42-131). Scoped here
   once under .pk-auth-form — identical computed styles.
   ============================================ */
.pk-auth-form .pk-login-form,
.pk-auth-form .pk-password-reset-form,
.pk-auth-form .pk-password-change-form {
  width: 100%;
}
.pk-auth-form .pk-login-header {
  text-align: left;
  margin-bottom: var(--pk-space-6, 2rem);
  display: flex;
  flex-direction: column;
  align-items: center;
  justify-content: center;
  gap: var(--pk-space-2, 0.5rem);
}
@media (min-width: 641px) {
  .pk-auth-form .pk-login-header {
    text-align: center;
  }
}
@media (max-width: 640px) {
  .pk-auth-form .pk-login-header {
    align-items: flex-start;
    text-align: left;
  }
}
.pk-auth-form .pk-login-title {
  font-family: 'Inter', sans-serif;
  font-size: var(--pk-font-2xl, 1.5rem);
  font-weight: var(--pk-weight-bold, 700);
  color: var(--pk-text-primary, #111827);
  margin: 0;
  overflow-wrap: break-word;
  text-wrap: balance;
  letter-spacing: -0.02em;
}
@media (max-width: 640px) {
  .pk-auth-form .pk-btn,
  .pk-auth-form button[type="submit"] {
    min-height: 48px;
    touch-action: manipulation;
  }
}

/* PasswordStepForm.php:119-133 — label row with "Wachtwoord vergeten?" */
.pk-password-label-row {
  display: flex;
  align-items: baseline;
  justify-content: space-between;
  margin-bottom: var(--pk-space-1, 0.25rem);
}
.pk-password-label-row .pk-form-label {
  margin-bottom: 0;
}
.pk-password-label-row .pk-link {
  font-size: var(--pk-font-sm, 0.875rem);
  white-space: nowrap;
}

/* PasswordResetForm.php:73-96 / PasswordChangeForm.php:81-104 — top back link */
.pk-auth-form .pk-login-footer-top {
  margin-top: 0;
  margin-bottom: var(--pk-space-4, 1rem);
  text-align: left;
  font-size: var(--pk-font-sm, 0.875rem);
  color: var(--pk-text-secondary, #6B7280);
}
@media (min-width: 641px) {
  .pk-auth-form .pk-login-footer-top {
    text-align: center;
  }
}
.pk-auth-form .pk-login-footer-top a {
  color: var(--pk-text-secondary, #6B7280);
  text-decoration: none;
  transition: color var(--pk-transition-fast, 150ms ease), text-decoration var(--pk-transition-fast, 150ms ease);
}
.pk-auth-form .pk-login-footer-top a:hover {
  color: var(--pk-text-primary, #111827);
  text-decoration: underline;
}

/* LoginForm.php:246-284 — "Nog geen account? Registreren" row below the
   submit button (gap-fill: not in the staged legacy CSS files, only inline
   in the legacy component). Rendered on every viewport (no mobile/desktop
   split — the legacy footer-top duplicate row is not reproduced). */
.pk-login-password-actions {
  display: flex;
  justify-content: center;
  align-items: center;
  gap: var(--pk-space-3, 0.75rem);
  margin-top: var(--pk-space-4, 1rem);
  flex-wrap: wrap;
}
.pk-login-register-text {
  font-size: var(--pk-font-sm, 0.875rem);
  color: var(--pk-text-secondary, #6B7280);
}
.pk-login-register-text a {
  color: var(--pk-text-secondary, #6B7280);
  text-decoration: none;
  font-weight: var(--pk-weight-medium, 500);
  transition: color var(--pk-transition-fast, 150ms ease), text-decoration var(--pk-transition-fast, 150ms ease);
}
.pk-login-register-text a:hover {
  color: var(--pk-text-primary, #111827);
  text-decoration: underline;
}

/* PasswordResetForm.php:98-107 — green success box */
.pk-success-message {
  background: var(--pk-bg-success, #F0FDF4);
  border: 1px solid var(--pk-border-success, #BBF7D0);
  color: var(--pk-text-success, #166534);
  padding: var(--pk-space-4, 1rem);
  border-radius: var(--pk-radius-md, 0.5rem);
  margin-bottom: var(--pk-space-4, 1rem);
  font-size: var(--pk-font-sm, 0.875rem);
  line-height: 1.5;
}

/* Inline notifications — legacy emitted these as style="" attributes
   (IdentifierForm.php:209-221, AuthFormBase.php:156-163); same declarations. */
.pk-notification-error {
  background: #FEE2E2;
  color: #DC2626;
  padding: 0.75rem 1rem;
  border-radius: 0.5rem;
  margin-bottom: 1rem;
  font-size: 0.875rem;
}
.pk-notification-info {
  background: #EFF6FF;
  color: #1D4ED8;
  padding: 0.75rem 1rem;
  border-radius: 0.5rem;
  margin-bottom: 1rem;
  font-size: 0.875rem;
  border: 1px solid #BFDBFE;
}

/* LoginForm.php:225-244 — remember/trust checkbox row */
.pk-login-remember-wrapper {
  display: flex;
  align-items: center;
  gap: var(--pk-space-2, 0.5rem);
  margin-bottom: var(--pk-space-4, 1rem);
}
.pk-login-remember-wrapper input[type="checkbox"] {
  width: 18px;
  height: 18px;
  flex-shrink: 0;
  cursor: pointer;
}
.pk-login-remember-wrapper label {
  flex: 1;
  font-size: var(--pk-font-sm, 0.875rem);
  color: var(--pk-text-primary, #111827);
  cursor: pointer;
}

/* ============================================
   Password input with eye toggle —
   Components/Auth/Elements/PasswordInput.php:95-176 verbatim
   ============================================ */
.pk-password-wrapper {
  position: relative;
  width: 100%;
}
.pk-password-input {
  padding-right: 3rem;
}
.pk-password-toggle {
  position: absolute;
  right: var(--pk-space-3, 0.75rem);
  top: 50%;
  transform: translateY(-50%);
  width: 44px;
  height: 44px;
  display: flex;
  align-items: center;
  justify-content: center;
  background: transparent;
  border: none;
  cursor: pointer;
  color: var(--pk-text-tertiary, #9CA3AF);
  transition: color var(--pk-transition-fast, 150ms ease);
  border-radius: var(--pk-radius-md, 0.625rem);
  padding: 0;
  touch-action: manipulation;
  -webkit-tap-highlight-color: transparent;
}
.pk-password-toggle:hover {
  color: var(--pk-text-secondary, #6B7280);
}
.pk-password-toggle:focus-visible {
  outline: 2px solid var(--pk-orange, #FF6B35);
  outline-offset: 2px;
}
.pk-password-toggle svg {
  width: 15px;
  height: 15px;
  flex-shrink: 0;
}
.pk-password-toggle .pk-eye-off-icon {
  display: none;
}
.pk-password-toggle.active .pk-eye-icon {
  display: none;
}
.pk-password-toggle.active .pk-eye-off-icon {
  display: block;
}
.pk-form-label-row {
  display: flex;
  justify-content: space-between;
  align-items: baseline;
}
.pk-caps-lock-warning {
  display: flex;
  align-items: center;
  gap: 0.25rem;
  font-size: 0.75rem;
  color: #2563EB;
  font-weight: 500;
}
.pk-caps-lock-warning svg {
  width: 14px;
  height: 14px;
  flex-shrink: 0;
}
@media (prefers-reduced-motion: reduce) {
  .pk-password-toggle { transition: none; }
}

/* ---------- 2. Auth card: top link, hints, 2FA digits, resend, strength meter (AuthCard.css) ---------- */
/* Gap-fill ONLY — the legacy pk-* CSS in Layouts/auth.twig owns the visual
   identity. Everything here is scoped under .c-auth-card and covers the few
   spots our generic card has no legacy counterpart for. */
.c-auth-card { width: 100%; }
.c-auth-card .pk-login-form { width: 100%; }
/* drs#1236 "Vertrouw dit apparaat": eigen vinkje in de huisstijl i.p.v. de
   kale browser-checkbox. Rustig (grijze tekst, dunne rand), oranje als hij
   aan staat; de echte input blijft voor toetsenbord en schermlezer. */
.c-auth-check {
  position: relative;
  display: inline-flex;
  align-items: center;
  gap: 0.625rem;
  align-self: flex-start;
  margin: var(--pk-space-5, 1.5rem) 0 var(--pk-space-4, 1rem);
  font-size: var(--pk-font-sm, 0.875rem);
  color: var(--pk-text-secondary, #6B7280);
  cursor: pointer;
  user-select: none;
  -webkit-tap-highlight-color: transparent;
}
.c-auth-check input {
  position: absolute;
  opacity: 0;
  width: 18px;
  height: 18px;
  margin: 0;
  cursor: pointer;
}
.c-auth-check__box {
  width: 18px;
  height: 18px;
  flex-shrink: 0;
  display: flex;
  align-items: center;
  justify-content: center;
  border: 1.5px solid var(--pk-border-medium, #D1D5DB);
  border-radius: 5px;
  background: #FFFFFF;
  transition: background-color var(--pk-transition-fast, 150ms ease), border-color var(--pk-transition-fast, 150ms ease), box-shadow var(--pk-transition-fast, 150ms ease);
}
.c-auth-check__box::after {
  content: "";
  width: 10px;
  height: 10px;
  background: url("data:image/svg+xml,%3Csvg xmlns='http://www.w3.org/2000/svg' viewBox='0 0 12 12' fill='none' stroke='%23fff' stroke-width='2' stroke-linecap='round' stroke-linejoin='round'%3E%3Cpath d='M2.5 6.2 5 8.5l4.5-5'/%3E%3C/svg%3E") no-repeat center / contain;
  opacity: 0;
  transform: scale(0.6);
  transition: opacity var(--pk-transition-fast, 150ms ease), transform var(--pk-transition-fast, 150ms ease);
}
.c-auth-check:hover .c-auth-check__box { border-color: var(--pk-border-dark, #9CA3AF); }
.c-auth-check input:checked + .c-auth-check__box {
  background: var(--pk-btn-primary-bg, #F26522);
  border-color: var(--pk-btn-primary-bg, #F26522);
}
.c-auth-check input:checked + .c-auth-check__box::after { opacity: 1; transform: scale(1); }
.c-auth-check input:focus-visible + .c-auth-check__box { box-shadow: var(--pk-shadow-focus); border-color: var(--pk-orange, #FF6B35); }
.c-auth-check__label { line-height: 1.4; }
@media (prefers-reduced-motion: reduce) {
  .c-auth-check__box, .c-auth-check__box::after { transition: none; }
}
/* Footnote (no legacy counterpart: our pages carry extra explainer copy) —
   rendered in the legacy helper-text voice, centered like the legacy
   footer-top links. */
.c-auth-card .c-auth-card__footnote {
    margin: var(--pk-space-4, 1rem) 0 0;
    font-size: var(--pk-font-sm, 0.875rem);
    color: var(--pk-text-secondary, #6B7280);
    text-align: center;
}
/* Hints render below their field; pull them toward the field they explain. */
.c-auth-card .c-auth-card__hint { margin: calc(-1 * var(--pk-space-2, 0.5rem)) 0 var(--pk-space-4, 1rem); }
/* Cross-link (footerLink) moved above the title (Pablo, 2026-07-21) — the
   legacy .pk-login-password-actions rule assumed it sat below the submit
   button (margin-top); flip to margin-bottom in its new top slot. */
.c-auth-card .c-auth-card__top-link { margin-top: 0; margin-bottom: var(--pk-space-4, 1rem); }
/* drs#1236: op mobiel links, net als "← Terug" (.pk-login-footer-top). */
@media (max-width: 640px) {
  .c-auth-card .c-auth-card__top-link { justify-content: flex-start; }
}

/* Legacy TOTP styles — Components/Auth/Forms/TotpInputForm.php:70-244
   verbatim. MOVED HERE from the customer TwoFactor page's colocated CSS
   (Pablo, 2026-07-22 office 2FA wave): AuthCard itself renders the
   `pk-totp-*` markup (the `type: 'totp'` field branch in AuthCard.twig), so
   with a SECOND consumer (Office/TwoFactor) appearing, CLAUDE.md's "⛔ NO
   DUPLICATED UI CODE" rule means these rules belong on the component that
   owns the markup, not copy-pasted per page. */
.pk-totp-form {
  width: 100%;
}
.pk-totp-header {
  margin-bottom: var(--pk-space-6, 2rem);
  text-align: left;
}
.pk-totp-icon {
  width: 64px;
  height: 64px;
  margin: 0 0 var(--pk-space-4, 1rem);
  display: flex;
  align-items: center;
  justify-content: center;
  background: var(--pk-orange-light, #FFF4ED);
  border-radius: 50%;
  color: var(--pk-orange, #FF6B35);
}
.pk-totp-icon svg {
  width: 32px;
  height: 32px;
}
.pk-totp-title {
  font-size: var(--pk-font-xl, 1.25rem);
  font-weight: var(--pk-weight-bold, 700);
  color: var(--pk-text-primary, #111827);
  margin-bottom: var(--pk-space-2, 0.5rem);
  overflow-wrap: break-word;
  text-wrap: balance;
}
.pk-totp-description {
  font-size: var(--pk-font-sm, 0.875rem);
  color: var(--pk-text-secondary, #6B7280);
  line-height: 1.5;
  margin: 0;
  overflow-wrap: break-word;
  text-wrap: pretty;
}
.pk-totp-email {
  font-weight: var(--pk-weight-semibold, 600);
  color: var(--pk-text-primary, #111827);
}
.pk-totp-inputs {
  display: flex;
  justify-content: space-between;
  gap: var(--pk-space-2, 0.5rem);
  width: 100%;
}
.pk-totp-digit {
  flex: 1;
  min-width: 0;
  height: 56px;
  font-size: 1.5rem;
  font-weight: var(--pk-weight-bold, 700);
  text-align: center;
  border: 2px solid var(--pk-border-medium, #D1D5DB);
  border-radius: var(--pk-radius-md, 0.5rem);
  background: #FFFFFF;
  color: var(--pk-text-primary, #111827);
  transition: border-color 150ms ease, box-shadow 150ms ease;
  font-family: var(--pk-font-mono, monospace);
  font-variant-numeric: tabular-nums;
}
.pk-totp-digit:focus-visible {
  outline: none;
  border-color: var(--pk-orange, #FF6B35);
  box-shadow: 0 0 0 3px rgba(255, 107, 53, 0.1);
}
.pk-totp-digit.filled {
  border-color: var(--pk-orange, #FF6B35);
  background: var(--pk-orange-light, #FFF4ED);
}
.pk-totp-digit.error {
  border-color: var(--pk-red, #DC2626);
  background: var(--pk-red-light, #FEE2E2);
}
.pk-totp-error {
  margin-top: var(--pk-space-4, 1rem);
  padding: var(--pk-space-3, 0.75rem) var(--pk-space-4, 1rem);
  background: #FEE2E2;
  border-radius: var(--pk-radius-md, 0.5rem);
  color: #DC2626;
  font-size: var(--pk-font-sm, 0.875rem);
  text-align: left;
}
.pk-totp-resend-link {
  color: var(--pk-text-secondary, #6B7280);
  text-decoration: underline;
  text-underline-offset: 2px;
  cursor: pointer;
  background: none;
  border: none;
  padding: 0;
  font: inherit;
  font-size: inherit;
}
.pk-totp-resend-link:hover {
  color: var(--pk-text-primary, #111827);
}
@media (max-width: 640px) {
  .pk-totp-icon {
    display: none;
  }
  .pk-totp-header {
    margin-bottom: var(--pk-space-4, 1rem);
  }
  .pk-totp-inputs {
    gap: var(--pk-space-2, 0.5rem);
  }
  .pk-totp-digit {
    height: 52px;
    font-size: 1.25rem;
  }
}
@media (prefers-reduced-motion: reduce) {
  .pk-totp-digit {
    transition: none;
  }
}
/* C3 resend row — the legacy inline 'Verstuur opnieuw' link
   (TotpInputForm.php:497-501) as a small form-post under the card. Shared
   class (was page-owned `.p-two-factor__resend`, promoted here alongside the
   totp styles above for the same reason: a second consumer, Office/TwoFactor,
   appeared using the identical markup/skin). */
.c-auth-card__resend {
  margin-top: var(--pk-space-3, 0.75rem);
  text-align: left;
  font-size: var(--pk-font-sm, 0.875rem);
  color: var(--pk-text-secondary, #6B7280);
  transition: opacity var(--pk-transition-base, 200ms ease);
}
/* drs#1236: in de card direct onder de vakjes (de knop blijft onderaan) en
   pas zichtbaar na data-resend-wait seconden (ko-auth.js). visibility i.p.v.
   display, zodat de regel zijn plek houdt en er niets verspringt. */
.c-auth-card__resend.is-waiting {
  visibility: hidden;
  opacity: 0;
}
/* drs#1232: de sms-regel direct onder "Geen code ontvangen?" */
.c-auth-card__resend + .c-auth-card__resend { margin-top: var(--pk-space-1, 0.25rem); }

/* Password strength indicator — lifted verbatim from legacy
   Components/Auth/Elements/PasswordStrengthIndicator.php getStyles()
   (segmented 4-bar + colour-coded level). The markup (AuthCard.twig
   pk-strength-*) was already byte-identical to legacy; only the CSS + the
   colouring JS (AuthCard.js) were missing on our side — the "unstyled Zwak"
   bug (Pablo 2026-07-23). Colours are legacy's literals, not tokens, to
   stay pixel-identical to the auth screens' standalone (non-DESIGN.md) shell. */
.pk-password-strength {
  margin-top: 0.5rem;
  margin-bottom: 1rem;
}
.pk-strength-bar {
  display: flex;
  gap: 4px;
}
.pk-strength-segment {
  flex: 1;
  height: 4px;
  border-radius: 2px;
  background: #E5E7EB;
  transition: background 150ms ease;
}
.pk-strength-segment.strength-weak   { background: #DC2626; }
.pk-strength-segment.strength-fair   { background: #F59E0B; }
.pk-strength-segment.strength-good   { background: #0D9488; }
.pk-strength-segment.strength-strong { background: #10B981; }
.pk-strength-label {
  font-size: 0.75rem;
  color: #9CA3AF;
  margin-top: 0.25rem;
}
@media (prefers-reduced-motion: reduce) {
  .pk-strength-segment { transition: none; }
}


/* ---------- 3. Notifications (Flash.css) ---------- */
/* Gap-fill ONLY. .pk-notification-error/-info are already declared verbatim
   in Layouts/auth.twig (IdentifierForm.php:209-221, AuthFormBase.php:156-163)
   — this component reuses them as-is, never redeclares them (no-duplicated-
   UI/CSS rule). '-success' has no legacy auth-screen counterpart (legacy's
   green box was `.pk-success-message`, a different one-off shape) — filled
   in here, same declaration family, scoped under .c-flash so it works
   portal-wide (not just inside the auth shell) wherever Base/Flash is used
   outside an auth page. */
.c-flash.pk-notification-success {
  background: var(--pk-bg-success, #F0FDF4);
  color: var(--pk-text-success, #166534);
  border: 1px solid var(--pk-border-success, #BBF7D0);
  padding: 0.75rem 1rem;
  border-radius: 0.5rem;
  margin-bottom: 1rem;
  font-size: 0.875rem;
}
/* Outside the auth shell (e.g. a future non-auth consumer), the auth.twig
   declarations for -error/-info are not in scope — mirror them here too so
   Base/Flash is genuinely self-contained (portal-wide reuse, per its own
   docblock), scoped under .c-flash so the auth-shell originals still win
   there via normal cascade/specificity (identical declarations, no conflict). */
.c-flash.pk-notification-error {
  background: #FEE2E2;
  color: #DC2626;
  padding: 0.75rem 1rem;
  border-radius: 0.5rem;
  margin-bottom: 1rem;
  font-size: 0.875rem;
}
.c-flash.pk-notification-info {
  background: #EFF6FF;
  color: #1D4ED8;
  padding: 0.75rem 1rem;
  border-radius: 0.5rem;
  margin-bottom: 1rem;
  font-size: 0.875rem;
  border: 1px solid #BFDBFE;
}

/* ===== PORT FIX (not in the rebuild yet) =====
   .pk-form-error is display:none until JS adds .show. A server-rendered field
   error (e.g. "Gebruik minimaal 8 tekens") has no .show and was invisible.
   Any non-empty error slot is shown. */
.pk-form-error:not(:empty) { display: block; }

/* ===== Legacy TemplateNotification bridge =====
   Controllers keep assigning TemplateNotification; ko_auth_notice() in
   auth_shell.php maps its colour onto these same pk-notification classes. */


/* ---------- 4. Profiel aanvullen (ProfileCompletion.css) ---------- */
/* Gap-fill only — legacy Components/Auth/Forms/ProfileCompletionForm.php
   getStyles(), lifted verbatim where not already covered by Layouts/auth.twig
   (pk-form-group/label/input/error/helper live there globally). */
.p-profile-completion { width: 100%; }

.pk-profile-header { text-align: left; margin-bottom: var(--pk-space-6, 2rem); }

.pk-profile-icon {
  width: 64px; height: 64px; margin: 0 0 var(--pk-space-4, 1rem);
  display: flex; align-items: center; justify-content: center;
  background: var(--pk-orange-light, #FFF4ED); border-radius: 50%; color: var(--pk-orange, #FF6B35);
}
.pk-profile-icon svg { width: 32px; height: 32px; }

.pk-profile-title {
  font-size: var(--pk-font-xl, 1.25rem); font-weight: var(--pk-weight-semibold, 700);
  color: var(--pk-text-primary, #111827); margin-bottom: var(--pk-space-2, 0.5rem);
}
.pk-profile-description { font-size: var(--pk-font-sm, 0.875rem); color: var(--pk-text-secondary, #6B7280); line-height: 1.5; }

.pk-profile-fields { display: flex; flex-direction: column; gap: var(--pk-space-4, 1rem); margin-bottom: var(--pk-space-4, 1rem); }
.pk-profile-fields > .pk-form-group, .pk-company-fields > .pk-form-group { margin-bottom: 0; }

/* progress indicator */
.pk-profile-progress { margin-bottom: var(--pk-space-5, 1.5rem); }
.pk-profile-progress-bar {
  width: 100%; height: 8px; background: var(--pk-bg-tertiary, #F3F4F6);
  border-radius: 999px; overflow: hidden;
}
.pk-profile-progress-fill { height: 100%; background: var(--pk-orange, #FF6B35); transition: width 200ms ease; }
.pk-profile-progress-label { margin-top: var(--pk-space-2, 0.5rem); font-size: var(--pk-font-xs, 0.75rem); color: var(--pk-text-secondary, #6B7280); }

/* select field (not styled by the shared auth shell) */
.pk-form-select {
  width: 100%; height: 48px; padding: 0 var(--pk-space-4, 1rem);
  border: 1px solid var(--pk-border-medium, #D1D5DB); border-radius: var(--pk-radius-md, 0.625rem);
  font-size: var(--pk-font-base, 1rem); font-family: inherit; color: var(--pk-text-primary, #111827);
  background: var(--pk-bg-primary, #FFFFFF); appearance: none; cursor: pointer;
}
.pk-form-select:focus { outline: none; border-color: var(--pk-orange, #FF6B35); }

/* checkbox toggle (company block) */
.custom-checkbox-wrapper { margin-bottom: 0; }
.custom-checkbox { display: flex; align-items: center; cursor: pointer; user-select: none; }
.custom-checkbox input[type="checkbox"] { position: absolute; opacity: 0; height: 0; width: 0; }
.custom-checkbox .checkmark {
  position: relative; height: 20px; width: 20px; background: #fff;
  border: 2px solid var(--pk-border-medium, #D1D5DB); border-radius: 4px; flex-shrink: 0;
  transition: background-color 0.2s ease, border-color 0.2s ease;
}
.custom-checkbox input:checked ~ .checkmark { background: var(--pk-orange, #FF6B35); border-color: var(--pk-orange, #FF6B35); }
.custom-checkbox .checkmark::after {
  content: ""; position: absolute; display: none; left: 6px; top: 2px; width: 5px; height: 10px;
  border: solid white; border-width: 0 2px 2px 0; transform: rotate(45deg);
}
.custom-checkbox input:checked ~ .checkmark::after { display: block; }
.custom-checkbox .label-text { margin-left: var(--pk-space-3, 0.75rem); font-size: var(--pk-font-sm, 0.875rem); color: var(--pk-text-primary, #111827); }

/* company fields — hidden until the toggle is checked */
.pk-company-fields { display: none; flex-direction: column; gap: var(--pk-space-4, 1rem); margin-bottom: var(--pk-space-4, 1rem); }
.pk-company-fields.pk-visible { display: flex; }

/* ---------- 5. Nieuw wachtwoord: strength label right-aligned (Pages/Auth/PasswordReset/PasswordReset.css) ---------- */
.p-password-reset .pk-strength-label { text-align: right; }

/* ===== PORT FIX (not in the rebuild yet): tall forms on short phones =====
   justify-content:flex-end pushes content that is TALLER than the container
   above its top edge, where it can never be scrolled to (e.g. "Voltooi je
   profiel" on a 390x844 phone: the title ends up 72px out of reach). An auto
   top margin anchors short forms to the bottom exactly the same way, but
   collapses to 0 when the content overflows, so the page scrolls normally. */
@media (max-width: 640px) {
  .pk-auth-container { justify-content: flex-start; }
  .pk-auth-content { margin-top: auto; }
}
