/* Self-hosted "Inter" font (variable font, weights 400-900), replacing the Google Fonts CDN
   link. This removes the only external, cross-origin resource loaded by every page:
   - Fixes the "Sub Resource Integrity Attribute Missing" pentest finding: Google's font CSS is
     generated per-request/per-user-agent, so a static SRI hash can't reliably be applied to it
     (Google itself advises against SRI for its fonts). Self-hosting removes the third-party
     resource entirely instead, which is the recommended fix.
   - Removes a per-page-load request to Google (fonts.googleapis.com / fonts.gstatic.com),
     improving privacy (no visitor IP sent to Google) and load performance (no extra DNS/TLS).
   - Makes it safe to enable Cross-Origin-Embedder-Policy: require-corp site-wide, since there's
     one less cross-origin sub-resource that would otherwise need explicit CORP/CORS opt-in.

   Only the "latin" and "latin-ext" subsets are needed (covers pt/en/fr/it/de, the app's
   supported languages) — both are variable fonts, so a single file per subset covers every
   weight from 400 to 900 (matching exactly what Google's own stylesheet does today). */

@font-face {
  font-family: 'Inter';
  font-style: normal;
  font-weight: 400 900;
  font-display: swap;
  src: url(/fonts/inter/inter-latin-ext.woff2) format('woff2');
  unicode-range: U+0100-02BA, U+02BD-02C5, U+02C7-02CC, U+02CE-02D7, U+02DD-02FF, U+0304, U+0308, U+0329, U+1D00-1DBF, U+1E00-1E9F, U+1EF2-1EFF, U+2020, U+20A0-20AB, U+20AD-20C0, U+2113, U+2C60-2C7F, U+A720-A7FF;
}
@font-face {
  font-family: 'Inter';
  font-style: normal;
  font-weight: 400 900;
  font-display: swap;
  src: url(/fonts/inter/inter-latin.woff2) format('woff2');
  unicode-range: U+0000-00FF, U+0131, U+0152-0153, U+02BB-02BC, U+02C6, U+02DA, U+02DC, U+0304, U+0308, U+0329, U+2000-206F, U+20AC, U+2122, U+2191, U+2193, U+2212, U+2215, U+FEFF, U+FFFD;
}
