Our Spring application is used to book various services. Normally, our clients list their services in their Instagram bio. When a user clicks the link in the Instagram bio, our application opens up in the Instagram browser.
At a critical point in the flow a 403 is caught by our application. This 403 does not always happen. But when it does, it only happens for some users on an iPhone navigating in the Instagram browser. No other combination of device/browser causes it. This 403 is causing us major issues.
The CSRF token is included as a hidden element in the form that is submitted which results in the 403. Perhaps Instagram's browser sometimes ignores this token but how or why is beyone me.
Has anyone else experienced anything like this?
Thanks