Files
arrr-erp/app/modules/accounting/gst_operator_agent_runtime

ARRR GST Operator Agent 1.4.0

Purpose
-------
Runs only on the GST operator workstation. It opens visible Chrome/Edge, redeems a short-lived GST job token from ARRR ERP, fills the selected Credential Vault username/password, waits for manual CAPTCHA/OTP, downloads selected GST return data, and uploads the package back to ERP for transfer to the configured Storage Agent.

Architecture
------------
ARRR ERP starts the agent through the Windows custom URL protocol arrrgst://. No browser-to-localhost HTTP/HTTPS request is used. No localhost TLS certificate, local web server, Tally access, or client storage access is required on the operator workstation.

Installation
------------
Run install_gst_operator_agent.ps1 as the Windows user who will operate GST downloads. Administrator rights are not required. Python 3.11+ and installed Chrome or Edge are required.

Browser prompt
--------------
The first time ARRR ERP opens arrrgst://, Chrome/Edge may ask whether to open ARRR GST Operator Agent. Choose Open/Allow.

Security
--------
The custom URL contains only a short-lived signed job token. GST username/password are redeemed by the local agent directly from ARRR ERP and are never inserted in ERP page HTML or in the custom URL. CAPTCHA/OTP remains manual.

Uninstall
---------
Run uninstall_gst_operator_agent.ps1. It removes the protocol registration and also cleans legacy v1.0.x localhost listener/startup/certificate state.


V1.4.0 VERIFIED POST-DASHBOARD DOWNLOAD SEQUENCE
- After CAPTCHA/OTP login, do not deep-link to return pages.
- Close optional Aadhaar/E-KYC reminder.
- From the authenticated GST Welcome page click Return Dashboard exactly as a user would.
- Wait for return.gst.gov.in /returns/auth/ session to load.
- Only then call GSTR-1/GSTR-2B/GSTR-3B APIs using the authenticated browser context.
- Manual JSON/ZIP import remains available in ERP as fallback.


V1.4.0 POST-DASHBOARD REPAIR
- Does not mark a job complete merely because Return Dashboard opened.
- Requires an actual saved JSON result for every selected return and period.
- GSTR-2B now enters its module only after the natural Return Dashboard session is established, then calls the GSTR-2B API same-origin.
- Does not call GST logout after completion.
- On failure the browser remains visible for 45 seconds with the exact failure message.
- Upload to ERP/client storage happens only after all expected return files are present.