ARRR GST Operator Agent 1.4.0 Purpose ------- Runs only on the GST operator workstation. It opens visible Chrome/Edge, redeems a short-lived GST job token from ARRR ERP, fills the selected Credential Vault username/password, waits for manual CAPTCHA/OTP, downloads selected GST return data, and uploads the package back to ERP for transfer to the configured Storage Agent. Architecture ------------ ARRR ERP starts the agent through the Windows custom URL protocol arrrgst://. No browser-to-localhost HTTP/HTTPS request is used. No localhost TLS certificate, local web server, Tally access, or client storage access is required on the operator workstation. Installation ------------ Run install_gst_operator_agent.ps1 as the Windows user who will operate GST downloads. Administrator rights are not required. Python 3.11+ and installed Chrome or Edge are required. Browser prompt -------------- The first time ARRR ERP opens arrrgst://, Chrome/Edge may ask whether to open ARRR GST Operator Agent. Choose Open/Allow. Security -------- The custom URL contains only a short-lived signed job token. GST username/password are redeemed by the local agent directly from ARRR ERP and are never inserted in ERP page HTML or in the custom URL. CAPTCHA/OTP remains manual. Uninstall --------- Run uninstall_gst_operator_agent.ps1. It removes the protocol registration and also cleans legacy v1.0.x localhost listener/startup/certificate state. V1.4.0 VERIFIED POST-DASHBOARD DOWNLOAD SEQUENCE - After CAPTCHA/OTP login, do not deep-link to return pages. - Close optional Aadhaar/E-KYC reminder. - From the authenticated GST Welcome page click Return Dashboard exactly as a user would. - Wait for return.gst.gov.in /returns/auth/ session to load. - Only then call GSTR-1/GSTR-2B/GSTR-3B APIs using the authenticated browser context. - Manual JSON/ZIP import remains available in ERP as fallback. V1.4.0 POST-DASHBOARD REPAIR - Does not mark a job complete merely because Return Dashboard opened. - Requires an actual saved JSON result for every selected return and period. - GSTR-2B now enters its module only after the natural Return Dashboard session is established, then calls the GSTR-2B API same-origin. - Does not call GST logout after completion. - On failure the browser remains visible for 45 seconds with the exact failure message. - Upload to ERP/client storage happens only after all expected return files are present.