/* Trim the admin console for dedicated realm admins (role `permissions-management`) down to the three
   pages they own. Cosmetic only — deep links and the Admin API stay reachable; see
   docs/specifications/2026-08-13-keycloak-realm-admin-console-design.md section 4.5.

   The `:has(#nav-item-realms)` guard is what keeps this inert on the master console: only a cross-realm
   admin gets the "Manage realms" nav item, so a nav WITHOUT it is a realm-scoped console. */
nav:not(:has(#nav-item-realms)) {
	#nav-item-clients,
	#nav-item-client-scopes,
	#nav-item-sessions,
	#nav-item-realm-settings,
	#nav-item-user-federation,
	#nav-item-workflows {
		display: none;
	}
}

/* Hide a nav section left empty by the rules above. PatternFly generates the section's `aria-labelledby`
   id per render, so there is no stable selector for "Configure" — match on the section holding none of
   the three pages that stay. */
nav:not(:has(#nav-item-realms)) section:not(:has(#nav-item-roles, #nav-item-users, #nav-item-groups)) {
	display: none;
}
