Instagram Browser CSRF issues (possibly hidden input issue)

Viewed 353

Our Spring application is used to book various services. Normally, our clients list their services in their Instagram bio. When a user clicks the link in the Instagram bio, our application opens up in the Instagram browser.

At a critical point in the flow a 403 is caught by our application. This 403 does not always happen. But when it does, it only happens for some users on an iPhone navigating in the Instagram browser. No other combination of device/browser causes it. This 403 is causing us major issues.

The CSRF token is included as a hidden element in the form that is submitted which results in the 403. Perhaps Instagram's browser sometimes ignores this token but how or why is beyone me.

Has anyone else experienced anything like this?

Thanks

1 Answers

I had this problem with one of my Ruby on Rails projects where people were navigating to a form directly from Instagram profile link, and once in a while we were getting 422's.

Logs showed that Instagram in-app browser submitted CSRF cookie that was different from the token in the hidden corresponding field in the form, which should not be the case, were the page loaded correctly in the in-app browser. We were able to replicate it live on one device, and from user's standpoint page loading and navigation looked completely normal. Could it be related to caching?

Previously we already had default Rails headers with max-age: 0, but decided to simply set

Cache-Control: no-cache, no-store

for every critical page and see if it changes anything.

The problem seems to have disappeared since.

Related