Add GST Operator Agent EXE v1.6.0 with Windows path-safe build

This commit is contained in:
A R R R Associates
2026-09-20 17:21:20 +05:30
parent c63fc2773c
commit 1462a823ee
9 changed files with 361 additions and 54 deletions
@@ -1,45 +1,57 @@
ARRR GST Operator Agent 1.5.1
ARRR GST Operator Agent 1.6.0
================================
Purpose
-------
Runs only on the GST operator workstation. It opens visible Chrome/Edge, redeems a short-lived GST job token from ARRR ERP, fills the selected Credential Vault username/password, waits for manual CAPTCHA/OTP, downloads selected GST return data, and uploads the package back to ERP for transfer to the configured Storage Agent.
Primary deployment: self-installing Windows EXE.
Architecture
The Windows setup EXE is built from gst_operator_agent.py using:
powershell -ExecutionPolicy Bypass -File .\build_gst_operator_agent_exe.ps1
Generated file:
dist\ARRR_GST_Operator_Agent_Setup_1.6.0.exe
Operator workstation installation
---------------------------------
1. Download ARRR_GST_Operator_Agent_Setup_1.6.0.exe from ARRR ERP.
2. Double-click the EXE.
3. The EXE copies itself to:
%LOCALAPPDATA%\ARRR\GSTOperatorAgent\ARRR_GST_Operator_Agent.exe
4. It writes config.json for https://office.arrrassociates.com.
5. It registers the current-user Windows protocol:
arrrgst://
6. It creates a normal Windows Installed Apps uninstall registration.
7. Return to GST Return Reconciliation and start the GST download.
No administrator rights are required.
Python is not required on operator workstations.
No localhost web server or trusted local certificate is used.
Runtime flow
------------
ARRR ERP starts the agent through the Windows custom URL protocol arrrgst://. No browser-to-localhost HTTP/HTTPS request is used. No localhost TLS certificate, local web server, Tally access, or client storage access is required on the operator workstation.
ARRR ERP issues a short-lived signed GST operator token.
Windows opens arrrgst://start?token=...
The installed EXE redeems the token over HTTPS.
GST Portal username/password are retrieved from ERP Credential Vault only after token redemption.
The visible Chrome/Edge GST browser is opened by the operator agent.
The operator completes CAPTCHA/OTP.
The agent downloads the selected GST return JSON/ZIP files and uploads the verified package back to ARRR ERP for client storage.
Installation
------------
Run install_gst_operator_agent.ps1 as the Windows user who will operate GST downloads. Administrator rights are not required. Python 3.11+ and installed Chrome or Edge are required.
Source/repair fallback
----------------------
The ERP still exposes a source ZIP for development/repair. The legacy PowerShell source installer remains supported and preserves the previous behavior, but the EXE is the normal workstation installation method from version 1.6.0 onward.
Browser prompt
--------------
The first time ARRR ERP opens arrrgst://, Chrome/Edge may ask whether to open ARRR GST Operator Agent. Choose Open/Allow.
Security
Commands
--------
The custom URL contains only a short-lived signed job token. GST username/password are redeemed by the local agent directly from ARRR ERP and are never inserted in ERP page HTML or in the custom URL. CAPTCHA/OTP remains manual.
Self-test:
ARRR_GST_Operator_Agent.exe --self-test
Uninstall
---------
Run uninstall_gst_operator_agent.ps1. It removes the protocol registration and also cleans legacy v1.0.x localhost listener/startup/certificate state.
Repair/install explicitly:
ARRR_GST_Operator_Agent.exe --install --erp-base-url https://office.arrrassociates.com
V1.5.1 OCTAGST-STYLE RETURN-DASHBOARD EXTRACTION
- Preserves the v1.4.0 Credential Vault login, manual CAPTCHA/OTP, natural Welcome -> Return Dashboard flow, ERP upload and failure diagnostics.
- GSTR-2B no longer transfers the browser to gstr2b.gst.gov.in.
- GSTR-2B is requested from the authenticated return.gst.gov.in Return Dashboard using the GST offline-download API pattern used by the supplied OctaGST extension.
- The agent follows GST-provided download URLs, saves returned ZIP/JSON files, and safely extracts JSON members locally.
- Same-origin GSTR-1 and GSTR-3B API calls remain unchanged.
- No automatic GST logout is performed.
- A job is completed only after every selected period/return has a saved result and ERP/client-storage upload is confirmed.
- Manual JSON/ZIP import remains available in ERP as fallback.
V1.5.1 NATURAL MONTHLY RETURN FLOW + GSTR-2B PENDING POLL
--------------------------------------------------------
- Restores robust Aadhaar/E-KYC Remind me later / Later dismissal.
- GSTR-2B generation-accepted responses are PENDING, not failures; polls up to 25 minutes.
- GSTR-1: selects FY/Quarter/Month on Return Dashboard, clicks Search, opens the actual GSTR-1 card, then performs offline generation/download from the initialized page context.
- GSTR-3B: selects FY/Quarter/Month, clicks Search, opens the actual GSTR-3B card, then reads summary/tax-payable from the initialized return page context.
- Existing Credential Vault, custom protocol, login/CAPTCHA, manual fallback, ERP upload and Storage Agent flow are unchanged.
Uninstall:
ARRR_GST_Operator_Agent.exe --uninstall