Use authenticated GST dashboard XHR for return downloads

This commit is contained in:
A R R R Associates
2026-09-12 12:35:44 +05:30
parent 782feaeeea
commit 4d0c53b9ba
4 changed files with 172 additions and 53 deletions
@@ -1,4 +1,4 @@
ARRR GST Operator Agent 1.4.0
ARRR GST Operator Agent 1.5.0
Purpose
-------
@@ -25,19 +25,12 @@ Uninstall
Run uninstall_gst_operator_agent.ps1. It removes the protocol registration and also cleans legacy v1.0.x localhost listener/startup/certificate state.
V1.4.0 VERIFIED POST-DASHBOARD DOWNLOAD SEQUENCE
- After CAPTCHA/OTP login, do not deep-link to return pages.
- Close optional Aadhaar/E-KYC reminder.
- From the authenticated GST Welcome page click Return Dashboard exactly as a user would.
- Wait for return.gst.gov.in /returns/auth/ session to load.
- Only then call GSTR-1/GSTR-2B/GSTR-3B APIs using the authenticated browser context.
V1.5.0 OCTAGST-STYLE RETURN-DASHBOARD EXTRACTION
- Preserves the v1.4.0 Credential Vault login, manual CAPTCHA/OTP, natural Welcome -> Return Dashboard flow, ERP upload and failure diagnostics.
- GSTR-2B no longer transfers the browser to gstr2b.gst.gov.in.
- GSTR-2B is requested from the authenticated return.gst.gov.in Return Dashboard using the GST offline-download API pattern used by the supplied OctaGST extension.
- The agent follows GST-provided download URLs, saves returned ZIP/JSON files, and safely extracts JSON members locally.
- Same-origin GSTR-1 and GSTR-3B API calls remain unchanged.
- No automatic GST logout is performed.
- A job is completed only after every selected period/return has a saved result and ERP/client-storage upload is confirmed.
- Manual JSON/ZIP import remains available in ERP as fallback.
V1.4.0 POST-DASHBOARD REPAIR
- Does not mark a job complete merely because Return Dashboard opened.
- Requires an actual saved JSON result for every selected return and period.
- GSTR-2B now enters its module only after the natural Return Dashboard session is established, then calls the GSTR-2B API same-origin.
- Does not call GST logout after completion.
- On failure the browser remains visible for 45 seconds with the exact failure message.
- Upload to ERP/client storage happens only after all expected return files are present.