* { box-sizing: border-box; }

body {
  margin: 0;
  font-family: system-ui, -apple-system, sans-serif;
  color: #1f2328;
  background: #f6f7f9;
  line-height: 1.55;
}

a { color: #b45309; }
a:hover { color: #f6821f; }

.topbar {
  background: #14171f;
  color: white;
  padding: 0 24px;
  display: flex;
  align-items: center;
  gap: 24px;
  flex-wrap: wrap;
  position: sticky;
  top: 0;
  z-index: 10;
}
.topbar .brand {
  display: flex;
  align-items: baseline;
  gap: 10px;
  font-weight: 700;
  padding: 14px 0;
  color: white;
  text-decoration: none;
  white-space: nowrap;
}
.topbar .brand span { font-weight: 400; color: #9aa4b2; font-size: 0.85rem; }
.topbar nav { display: flex; gap: 4px; flex-wrap: wrap; }
.topbar nav a {
  color: #cbd5e1;
  text-decoration: none;
  padding: 8px 12px;
  border-radius: 6px;
  font-size: 0.92rem;
}
.topbar nav a:hover { background: #2a2f3a; color: white; }
.topbar nav a.active { background: #f6821f; color: white; }

main { max-width: 860px; margin: 0 auto; padding: 32px 24px 72px; }
main.wide { max-width: 1100px; }

h1 { margin: 0 0 8px; font-size: 1.9rem; }
h2 { margin: 32px 0 8px; font-size: 1.3rem; }
h3 { margin: 24px 0 6px; font-size: 1.05rem; }
p { margin: 0 0 12px; }
ul, ol { margin: 0 0 12px; padding-left: 22px; }
li { margin-bottom: 6px; }

.lede { font-size: 1.05rem; color: #4b5563; margin-bottom: 24px; }
.muted { color: #6b7280; }
.crumb { font-size: 0.85rem; color: #6b7280; margin-bottom: 16px; }

.card {
  background: white;
  border-radius: 10px;
  padding: 18px 22px;
  box-shadow: 0 1px 3px rgba(0, 0, 0, 0.08);
  margin-bottom: 16px;
}
.card h3 { margin-top: 0; }
.card > :last-child { margin-bottom: 0; }

.grid { display: grid; grid-template-columns: repeat(auto-fit, minmax(240px, 1fr)); gap: 16px; margin-bottom: 16px; }
.grid .card { margin-bottom: 0; }

.callout {
  border-left: 4px solid #f6821f;
  background: #fff7ed;
  padding: 12px 16px;
  border-radius: 0 8px 8px 0;
  margin-bottom: 16px;
}
.callout.warn { border-left-color: #dc2626; background: #fef2f2; }
.callout.ok { border-left-color: #16a34a; background: #f0fdf4; }
.callout > :last-child { margin-bottom: 0; }
/* The callout title, which callout() emits as the first child. Scoped to exactly
   that: as a descendant selector this also made every <strong> in the body a block,
   so an emphasised phrase mid-sentence broke the line before and after itself. */
.callout > strong:first-child { display: block; margin-bottom: 4px; }

pre {
  background: #14171f;
  color: #e5e7eb;
  padding: 14px 16px;
  border-radius: 8px;
  overflow-x: auto;
  font-size: 0.85rem;
  line-height: 1.45;
  margin: 0 0 16px;
}
code { font-family: ui-monospace, SFMono-Regular, Menlo, monospace; font-size: 0.9em; }
p code, li code, td code { background: #eef0f2; padding: 1px 5px; border-radius: 4px; }

.prompt {
  background: white;
  border: 1px solid #fed7aa;
  border-left: 4px solid #f6821f;
  border-radius: 0 8px 8px 0;
  padding: 14px 18px;
  margin-bottom: 16px;
  font-size: 1.02rem;
}
.prompt .label {
  display: block;
  font-size: 0.72rem;
  text-transform: uppercase;
  letter-spacing: 0.06em;
  color: #b45309;
  margin-bottom: 6px;
}
.prompt q { font-style: italic; }

.tags { display: flex; gap: 6px; flex-wrap: wrap; margin-bottom: 16px; }
.tag {
  display: inline-block;
  padding: 2px 10px;
  border-radius: 999px;
  font-size: 0.75rem;
  background: #eef0f2;
  color: #374151;
  white-space: nowrap;
}
.tag.hr { background: #dbeafe; color: #1d4ed8; }
.tag.crm { background: #dcfce7; color: #15803d; }
.tag.collab { background: #fef9c3; color: #92620a; }
.tag.wiki { background: #ede9fe; color: #6d28d9; }
.tag.intentional { background: #fee2e2; color: #b91c1c; }
.tag.accidental { background: #ffedd5; color: #9a3412; }
.tag.injection { background: #1f2937; color: #f9fafb; }
.tag.cross { background: #e0f2fe; color: #0369a1; }
.tag.finance { background: #d1fae5; color: #065f46; }
.tag.misuse { background: #fce7f3; color: #9d174d; }
.tag.access { background: #e2e8f0; color: #334155; }

table { width: 100%; border-collapse: collapse; background: white; border-radius: 10px; overflow: hidden; box-shadow: 0 1px 3px rgba(0, 0, 0, 0.08); margin-bottom: 16px; }
th, td { text-align: left; padding: 9px 14px; border-bottom: 1px solid #eef0f2; vertical-align: top; font-size: 0.92rem; }
th { background: #fafbfc; font-size: 0.75rem; text-transform: uppercase; letter-spacing: 0.04em; color: #6b7280; }

.demo-list { list-style: none; padding: 0; }
.demo-list li { margin-bottom: 10px; }
.demo-list a { font-weight: 600; text-decoration: none; }
.demo-list a:hover { text-decoration: underline; }
.demo-list .meta { display: block; color: #6b7280; font-size: 0.9rem; }

footer.site {
  border-top: 1px solid #e5e7eb;
  padding: 20px 24px 40px;
  text-align: center;
  color: #6b7280;
  font-size: 0.85rem;
}

.steps { counter-reset: step; list-style: none; padding-left: 0; }
.steps > li {
  counter-increment: step;
  position: relative;
  padding-left: 34px;
  margin-bottom: 14px;
}
.steps > li::before {
  content: counter(step);
  position: absolute;
  left: 0;
  top: 1px;
  width: 24px;
  height: 24px;
  border-radius: 50%;
  background: #14171f;
  color: white;
  font-size: 0.8rem;
  display: flex;
  align-items: center;
  justify-content: center;
}

/* The demo index table: three columns, so a session can be planned by control
   and by value rather than by title alone. */
.demo-table { width: 100%; border-collapse: collapse; margin-bottom: 28px; }
.demo-table th {
  text-align: left; padding: 8px 12px; font-size: 0.75rem; text-transform: uppercase;
  letter-spacing: 0.04em; color: #6b7280; border-bottom: 2px solid #e5e7eb; white-space: nowrap;
}
.demo-table td { padding: 12px; border-bottom: 1px solid #eef0f2; vertical-align: top; font-size: 0.92rem; }
.demo-table tr:hover td { background: #fafbfc; }
.demo-table td:first-child { width: 28%; }
.demo-table .control-cell { width: 27%; color: #374151; }
.demo-table .row-meta { display: block; font-size: 0.78rem; color: #9aa4b2; margin-top: 3px; }
.demo-table .muted { color: #9aa4b2; }
@media (max-width: 800px) {
  .demo-table, .demo-table tbody, .demo-table tr, .demo-table td { display: block; width: auto; }
  .demo-table thead { display: none; }
  .demo-table tr { border-bottom: 1px solid #e5e7eb; padding: 8px 0; }
  .demo-table td { border: none; padding: 4px 0; }
  .demo-table td:first-child { width: auto; font-weight: 600; }
}

/* Code blocks you are meant to copy, rather than read. */
.code-copy { position: relative; }
.code-copy pre { margin-top: 0; }
.copy-btn {
  position: absolute; top: 8px; right: 8px; z-index: 2;
  font: inherit; font-size: 0.75rem; font-weight: 600;
  padding: 4px 10px; border-radius: 6px; cursor: pointer;
  background: #fff; color: #334155; border: 1px solid #cbd5e1;
}
.copy-btn:hover { background: #f8fafc; border-color: #94a3b8; }
.copy-btn.copied { background: #dcfce7; border-color: #86efac; color: #15803d; }

/* Diagrams - see figure() in src/layout.mjs. The white background is deliberate
   rather than inherited: these are exported with transparency, and a dark or
   tinted page would put the labels on top of it. */
.figure { margin: 0 0 20px; }
.figure a { display: block; }
.figure img {
  display: block;
  width: 100%;
  height: auto;
  background: #fff;
  border: 1px solid #e2e8f0;
  border-radius: 10px;
  padding: 10px;
  box-sizing: border-box;
}
.figure a:hover img { border-color: #94a3b8; }
.figure-link img { cursor: zoom-in; }

/* The figure lightbox - see figure() in src/layout.mjs and the handler in site.js.
   The markup is a plain link to the image file, so this is an enhancement rather
   than a requirement: with no JavaScript the link still opens the image.
   [hidden] needs restating because `display: flex` would otherwise beat it. */
.lightbox {
  position: fixed;
  inset: 0;
  z-index: 50;
  display: flex;
  align-items: center;
  justify-content: center;
  padding: 28px;
  background: rgba(15, 23, 42, 0.9);
}
.lightbox[hidden] { display: none; }
.lightbox img {
  max-width: 100%;
  max-height: 100%;
  /* These diagrams are exported with a transparent background, which on a dark
     overlay would put the labels on top of nothing. */
  background: #fff;
  border-radius: 8px;
  padding: 10px;
  box-sizing: border-box;
  cursor: default;
}
.lightbox-close {
  position: absolute;
  top: 14px;
  right: 18px;
  width: 36px;
  height: 36px;
  padding: 0;
  font-size: 1.6rem;
  line-height: 1;
  color: #fff;
  background: transparent;
  border: 0;
  border-radius: 6px;
  cursor: pointer;
}
.lightbox-close:hover { background: rgba(255, 255, 255, 0.16); }
.lightbox-close:focus-visible { outline: 2px solid #fff; outline-offset: 2px; }
/* Stops the page scrolling behind the overlay. */
body.lightbox-open { overflow: hidden; }
.figure figcaption {
  margin-top: 8px;
  font-size: 0.8125rem;
  color: #64748b;
}

/* A card you have to open - see disclosure() in src/layout.mjs. Used where two
   alternatives are both complete and only one applies to the reader. */
.disclosure {
  background: #fff;
  border: 1px solid #e2e8f0;
  border-radius: 10px;
  box-shadow: 0 1px 3px rgba(0, 0, 0, 0.08);
  margin-bottom: 12px;
  overflow: hidden;
}
.disclosure > summary {
  cursor: pointer;
  padding: 16px 22px;
  display: flex;
  flex-wrap: wrap;
  align-items: baseline;
  gap: 4px 12px;
  list-style: none;
}
.disclosure > summary::-webkit-details-marker { display: none; }
/* The chevron, drawn rather than imported, and rotated when open. */
.disclosure > summary::before {
  content: "";
  width: 7px; height: 7px; flex-shrink: 0;
  margin-right: 4px;
  border-right: 2px solid #64748b;
  border-bottom: 2px solid #64748b;
  transform: rotate(-45deg);
  transition: transform 0.15s ease;
}
.disclosure[open] > summary::before { transform: rotate(45deg); }
.disclosure > summary:hover { background: #f8fafc; }
.disclosure-title { font-weight: 650; font-size: 1.0625rem; letter-spacing: -0.01em; }
.disclosure-hint { color: #64748b; font-size: 0.8125rem; }
.disclosure-body { padding: 0 22px 18px; border-top: 1px solid #eef2f6; padding-top: 16px; }
.disclosure-body > :first-child { margin-top: 0; }
.disclosure-body > :last-child { margin-bottom: 0; }

/* ---------------------------------------------------- the walkthrough page */
.wt-step { margin: 40px 0; padding-top: 4px; }
.wt-step + .wt-step { border-top: 1px solid #e5e7eb; padding-top: 32px; }
.wt-head { display: flex; gap: 14px; align-items: flex-start; margin-bottom: 14px; }
.wt-num {
  flex-shrink: 0; width: 30px; height: 30px; border-radius: 50%;
  background: #1f2937; color: #fff; font-weight: 700; font-size: 0.875rem;
  display: inline-flex; align-items: center; justify-content: center; margin-top: 2px;
}
.wt-head h2 { margin: 0; font-size: 1.15rem; }
.wt-where { margin: 3px 0 0; font-size: 0.8125rem; color: #6b7280; }
.wt-kind { font-weight: 600; padding: 1px 7px; border-radius: 4px; font-size: 0.75rem; }
/* "Enforced at:" - the one line that says where in the chain a step's control sits.
   Deliberately plain and directly under the badge: the badge names the control, this
   names the place, and the demo's argument is that those are different questions. */
.wt-point { margin: 4px 0 0; font-size: 0.8125rem; color: #475569; }
.wt-point strong { color: #0f172a; }
.wt-kind.aigw { background: #fce7f3; color: #9d174d; }
.wt-kind.guardrail { background: #ffe4e6; color: #9f1239; }
.wt-kind.gwdlp { background: #dbeafe; color: #1d4ed8; }
.wt-kind.access { background: #e2e8f0; color: #334155; }
.wt-kind.mixed { background: #ede9fe; color: #6d28d9; }
.wt-kind.none { background: #f1f5f9; color: #64748b; }
.wt-step h3 {
  font-size: 0.75rem; text-transform: uppercase; letter-spacing: 0.06em;
  color: #6b7280; margin: 22px 0 8px;
}
.wt-note {
  border-left: 3px solid #e5e7eb; padding: 2px 0 2px 14px; margin-top: 18px;
  font-size: 0.9rem; color: #4b5563;
}
.wt-note p { margin: 0; }

/* A hostname that is also a link: reads as code, behaves as a link. */
.host-link {
  font-family: ui-monospace, SFMono-Regular, Menlo, monospace;
  font-size: 0.9em; background: #f1f5f9; border: 1px solid #e2e8f0;
  border-radius: 4px; padding: 1px 5px; text-decoration: none; color: #0369a1;
}
.host-link:hover { background: #e0f2fe; border-color: #7dd3fc; text-decoration: none; }

/* The "with protection" half of every walkthrough step. Deliberately loud:
   it is the half the audience came for, and on a long page the eye needs
   somewhere to land. */
.wt-protected {
  background: #f0fdf4; border: 1px solid #bbf7d0; border-left: 4px solid #16a34a;
  border-radius: 8px; padding: 14px 18px; margin-top: 18px;
}
.wt-protected h3 {
  margin: 0 0 8px; color: #15803d; display: flex; align-items: center; gap: 7px;
}
.wt-protected h3 svg { width: 15px; height: 15px; fill: currentColor; }
.wt-protected p:last-child, .wt-protected ul:last-child { margin-bottom: 0; }
/* Inline code inside a protected block, tinted to match it. Scoped the same way as
   the base inline-code rule above: unscoped, this also painted `pre > code`, so the
   JSON in a protected block got a pale green background behind pale text on a dark
   block and became unreadable. */
.wt-protected p code, .wt-protected li code, .wt-protected td code { background: #dcfce7; }
.wt-kind.swg { background: #fef3c7; color: #92400e; }
