/*
  GeoDataOne login theme stylesheet.

  Loaded in addition to the parent keycloak theme's ``css/login.css``
  (see ``theme.properties``), so everything not named here keeps stock
  Keycloak styling.

  ------------------------------------------------------------------
  Task #51 (SEC-REG-BOT-PROTECTION-A) follow-up: hide the User Profile
  copy of the ``website_confirm`` honeypot.
  ------------------------------------------------------------------

  ``register.ftl`` injects its own off-screen ``website_confirm`` input
  immediately after the opening <form> tag. The server-side half of the
  defense is the paired User Profile attribute in
  ``keycloak/realms/geodataone.json``, whose ``^$`` pattern validator
  rejects any submission that filled the field in.

  That attribute grants ``edit`` to ``user``. This is deliberate and load
  bearing: Keycloak silently DISCARDS attributes the submitting context
  is not allowed to edit, so an admin-only attribute would never have its
  validator run against a registration POST and the bot gate would be
  dead with no visible signal. The cost of that permission is that
  Keycloak's ``userProfileFormFields`` macro also renders the attribute
  as an ordinary, visible form row -- producing two inputs with
  ``id="website_confirm"`` on the page and showing real users a labelled
  box they are told not to fill in.

  So the rendered row is suppressed here, in the presentation layer,
  rather than by weakening the attribute's permissions.

  Positioned off-screen rather than ``display: none`` so the input is
  still a live, fillable form control for a bot that walks the DOM --
  which is the entire point of a honeypot. The visually-hidden idiom
  matches the inline style ``register.ftl`` already uses on its own copy.

  The selector deliberately targets the form group (label + input
  wrapper) and not just the input, so the "Do not fill this" label goes
  with it. ``:has()`` is supported by every browser that can run the
  Keycloak 26 login page; if it were ever unavailable the rule simply
  does not apply and the page degrades to today's behaviour -- it can
  never break registration or disable the validator.
*/
#kc-register-form > div.form-group:has(input[name="website_confirm"]) {
  position: absolute !important;
  left: -9999px !important;
  width: 1px !important;
  height: 1px !important;
  overflow: hidden !important;
}
