Showing posts with label instagram. Show all posts
Showing posts with label instagram. Show all posts

Thursday, July 19, 2018

Missing Connected Instagram Account Fields for Pages in Graph API

Leave a Comment

I am trying to get our users Facebook Pages with connected Instagram Business Accounts using the API:

https://graph.facebook.com/v2.7/me/accounts?fields=id,name,connected_instagram_account{ig_id,name}&limit=20  

For some pages, I did not get the connected Instagram Accounts.

We have tried to set up again (ie. by removing the linked facebook page and then link it from Instagram Settings), but I am not able to get the connected instagram accounts info yet.

Can anyone help me to resolve this?

1 Answers

Answers 1

Prerequisite: You first need the business Instagram account to be linked with Facebook Page. https://help.instagram.com/356902681064399 - That one can do from the profile page of Instagram account.

Currently, for FaceBook graph API we need a linked business page to Instagram account. As above APIs uses page tokens.

Please Look into this

Read More

Wednesday, March 21, 2018

Instagram OAuthException code 400, without specific reason

1 comment

Our app allows users to sign in with Instagram. Everything works well in general but one user just submitted the issue:

  • When he tries to authorize in IG from our app, he receives the following error:

{"error_type":"OAuthException", "code":400, "error_message":"There was an error with your request. Please try again."}

Trying again does not help. He still sees the issue and cannot connect his IG account.

Can anyone help at least with the direction we have to follow in our investigation?

1 Answers

Answers 1

Answer by h0mayun seems to work:

For me unchecking Disable implicit OAuth in instagram developer -> manage clients fixed the issue

Read More

Friday, March 16, 2018

Get Facebook Media-id for instagram post from url

Leave a Comment

If I have a instagram post is there anyway to get the facebook id for an instagram post? To be clear, if I were to look at https://www.instagram.com/p/Bcqn51ynrd5/ I am able to find the instagram media-id by doing one of two things:

However, neither of these are the media-id associated with facebook's new instagram graph insights. If I already have the facebook media-id I am able to get the instagram media-id through facebook graph by calling graph.facebook.com/{facebook-media-id}?fields=ig_id but I am unable to find the inverse. Is this possible?

1 Answers

Answers 1

I don't think it is possible. It is listed as limitation in the Insights API documentation.

To list current limitations:

  • We only store 2 years worth of metrics data.
  • You can only get insights for a single Instagram Business account at a time.
  • You cannot get insights for Facebook Pages.
  • Stories insights are only available for 24 hours, even if the stories are archived or highlighted. If you want to get the latest insights for a story before it expires, set up a Webhook for the Instagram topic and subscribe to the story_insights field.
Read More

Thursday, March 8, 2018

Instagram Integration on Laravel 5

Leave a Comment

I kept getting this issue after installing this package below

https://github.com/vinkla/instagram

into my Laravel 5.1 project.

2018-02-27 at 1 55 36 pm

I followed everything in the instruction.

I am on Mac OS X, PHP 7.1, Laravel 5.1

Did I forget something?

How would one go about and debug this further ?


I'm open to any suggestions at this moment.

Any hints/suggestions / helps on this be will be much appreciated!

3 Answers

Answers 1

Your report() method is being passed a PHP7 Throwable instead of an Exception.

Laravel 5.1 was not updated to support PHP7 Throwables until 5.1.8.

Considering the error, and the line number specified in HandleExceptions.php, it seems as if you are using a version previous to this (5.1.0 - 5.1.7).

You will need to update Laravel to at least 5.1.8 to fix this error. 5.1.8 was updated to convert Throwables to Symfony\Component\Debug\Exception\FatalThrowableError exceptions, which are then passed to the report() method.

Answers 2

You could change app\Exceptions\Handler.php to not have the type declaration Exception and handle some logic within it to convert the Error to an Exception. It looks like this is a known issue in laravel 5.2 <= with php 7. https://github.com/laravel/framework/issues/9650

from:

/**  * Report or log an exception.  *  * This is a great spot to send exceptions to Sentry, Bugsnag, etc.  *  * @param  \Exception  $exception  * @return void  */ public function report(Exception $exception) {     parent::report($exception); } 

to:

/**  * Report or log an exception.  *  * This is a great spot to send exceptions to Sentry, Bugsnag, etc.  *  * @param  \Exception  $exception  * @return void  */ public function report($exception) {     if ($exception instanceof Exception) {         parent::report($exception);     } else {        // convert to exception and then parent::report.     }  } 

You will most likely need to do the same thing with the Handler render method.

Answers 3

It seems to be a bug in Laravel. Do you have the last release of Laravel 5.1?

For helping debug, you might go to the vendor/Illuminate/Foundation/Bootstrap/HandleExceptions@handleException and add dd($e) at the first line of method.

Ex:

public function handleException($e) {     dd($e);     //.. } 
Read More

Tuesday, February 20, 2018

Access Instagram media without using Instagram API

Leave a Comment

I have previously used the Instagram API to access public images by tag, location, etc. I created a new application and retrieved an access_token, but these public media searches no longer return any data. However, they return 200 statuses.

On the documentation, it says "applications not accepted" for the the public_content scope, which is required for these searches. So, it appears that the Instagram API is being deprecated.

This makes zero sense to me (which is why I'm posting here), since these types of searches are at the core of so many applications and services. I'm also confused by how these requests still return 200 responses.

I was wondering if there are other methods to access public content on Instagram, such as using the Facebook API. Does Instagram wants to entirely prevent developers from accessing public photos? Or is this just to port the Instagram API features to another API, like Facebook?

2 Answers

Answers 1

If you can't use API you can try to scrap HTML.

You can get html for needed tag by link https://www.instagram.com/explore/tags/[TAG]/

Eg

curl https://www.instagram.com/explore/tags/telegram/ 

Then you must find sting wich starts from "<script type="text/javascript">window._sharedData =" There will be JSON wich easy to parse with any popular languges.

From this data you can get list of "shortcode" of posts. Eg "BfLErJ_hzak"

Next you can get post-detail by link https://www.instagram.com/p/[SHORTCODE]/?__a=1

Eg.

curl https://www.instagram.com/p/BfLErJ_hzak/?__a=1 

It returns JSON data. See example

{"graphql":{"shortcode_media":{"__typename":"GraphImage","id":"1714484640997652132","shortcode":"BfLErJ_hzak","dimensions":{"height":1080,"width":1080},"gating_info":null,"media_preview":"ACoqamHCl0YsgAyQeMc//qp8DFiXPUmrTTbarwgmUlfu8HHHGaHqES0yqT6ZH61Pa9vp/SlQIi7Rg4/X/P6Utuc84K4B4NG2gbkyj7v5/pQZcEinL1HsP8KhKE8+tMRkzHiqQcJzz/jVi4gOMpwfaqRmLrsfr09zTA3YYzjcR+A5/wA/hVvB2lhxxkf4H61BZy70GRgjj644zVxOmDUgCtnnvipQABiqhyhyPX9Kk88e1MCo6dR3rKeLKhx+PtW0/QfQVmwnlx7mmI0IYR5akcHAqfdtOTTLf/Vr9KbLUjJnCnv15qgUWi2JKHPPOP50/NNAf//Z","display_url":"https://instagram.fhel3-1.fna.fbcdn.net/vp/d44e27e253f499ab84bd5944c8a93313/5B044F81/t51.2885-15/e35/27581038_2488346268057255_6612776414812831744_n.jpg","display_resources":[{"src":"https://instagram.fhel3-1.fna.fbcdn.net/vp/0e2d4f8e3b780cc4fba827e2afbcd7bd/5B180DAB/t51.2885-15/s640x640/sh0.08/e35/27581038_2488346268057255_6612776414812831744_n.jpg","config_width":640,"config_height":640},{"src":"https://instagram.fhel3-1.fna.fbcdn.net/vp/2d7cba2b057809aa589ab589baed3aff/5B087C45/t51.2885-15/s750x750/sh0.08/e35/27581038_2488346268057255_6612776414812831744_n.jpg","config_width":750,"config_height":750},{"src":"https://instagram.fhel3-1.fna.fbcdn.net/vp/d44e27e253f499ab84bd5944c8a93313/5B044F81/t51.2885-15/e35/27581038_2488346268057255_6612776414812831744_n.jpg","config_width":1080,"config_height":1080}],"is_video":false,"should_log_client_event":false,"tracking_token":"eyJ2ZXJzaW9uIjo1LCJwYXlsb2FkIjp7ImlzX2FuYWx5dGljc190cmFja2VkIjpmYWxzZSwidXVpZCI6IjdiZjJhOGI4MTc5YzRmMTViYWZmOGViYjg4N2RkOWZhMTcxNDQ4NDY0MDk5NzY1MjEzMiJ9LCJzaWduYXR1cmUiOiIifQ==","edge_media_to_tagged_user":{"edges":[]},"edge_media_to_caption":{"edges":[{"node":{"text":"Cuando se te pegan las mantas \ud83d\ude48\ud83d\ude48\ud83d\ude48\n.\n10,90\u20ac\n.\nhttp://s.click.aliexpress.com/e/EaEYFaE\n\nFACEBOOK.COM/ROPATEANDO\nBLOG.ROPATEANDO.COM\n.\n#mantabebe#ropateando #elarmarioderopateando #telegram #pic #picoftheday #outfit #outfitoftheday #outfitpost #ropa #instame #instalike #instalove #instalook #fashion #moda #instablogger #ootd #love #instagood #me #cute #like #influencer #beautiful #style #streetstyle"}}]},"caption_is_edited":true,"edge_media_to_comment":{"count":2,"page_info":{"has_next_page":false,"end_cursor":null},"edges":[{"node":{"id":"17850908371233214","text":"Link","created_at":1518602595,"owner":{"id":"55206905","profile_pic_url":"https://instagram.fhel3-1.fna.fbcdn.net/vp/0f2d694caef7809255bd21e18579ebf3/5B2176B2/t51.2885-19/s150x150/22802830_358422461266066_4296876623711436800_n.jpg","username":"lorenacuaja"}}},{"node":{"id":"17924024554016118","text":"Enviado","created_at":1518602616,"owner":{"id":"2096327952","profile_pic_url":"https://instagram.fhel3-1.fna.fbcdn.net/vp/b142448b7225a12c25a81c4e4f84a577/5B0BFE21/t51.2885-19/s150x150/11930847_519140961600089_515209800_a.jpg","username":"ropateando"}}}]},"comments_disabled":false,"taken_at_timestamp":1518602517,"edge_media_preview_like":{"count":19,"edges":[{"node":{"id":"330280392","profile_pic_url":"https://instagram.fhel3-1.fna.fbcdn.net/vp/ff423c2bc927ec317701338712461b28/5B246257/t51.2885-19/s150x150/26071831_1616366641789125_3093631880650555392_n.jpg","username":"vlimamart"}},{"node":{"id":"5979047553","profile_pic_url":"https://instagram.fhel3-1.fna.fbcdn.net/vp/f4d1635630b571fb16b2b1f1cf99fd8e/5B039B10/t51.2885-19/s150x150/21227380_116088969094159_5157150429842243584_a.jpg","username":"dochylos"}},{"node":{"id":"226729325","profile_pic_url":"https://instagram.fhel3-1.fna.fbcdn.net/vp/8f76c54bb62f45ec33fe5e8b0fa2b733/5B234418/t51.2885-19/11428696_136540733352298_2103764682_a.jpg","username":"elsagcallejo"}},{"node":{"id":"2958399052","profile_pic_url":"https://instagram.fhel3-1.fna.fbcdn.net/vp/2ca058e070ce56861ae48fbf2c8ea931/5B1D2C9B/t51.2885-19/s150x150/19429360_320564085053737_4974100564364230656_a.jpg","username":"suraj_sk2"}},{"node":{"id":"1375472655","profile_pic_url":"https://instagram.fhel3-1.fna.fbcdn.net/vp/a3fd8350cb45401d0ab50aad95ef427f/5B111BD7/t51.2885-19/s150x150/26151195_2090241727875639_7471255521614364672_n.jpg","username":"alandashenka"}},{"node":{"id":"265784569","profile_pic_url":"https://instagram.fhel3-1.fna.fbcdn.net/vp/4b062db4cbf5bb2a50fbbffe2d6109b9/5B253FE0/t51.2885-19/s150x150/25017909_2061467437421348_4184874695654375424_n.jpg","username":"themayorsstatement"}},{"node":{"id":"6883303908","profile_pic_url":"https://instagram.fhel3-1.fna.fbcdn.net/vp/b4577832af28080a9607edcb758799cc/5B1A8203/t51.2885-19/s150x150/25037105_1997130850508677_1213534002938380288_n.jpg","username":"real247fitness"}},{"node":{"id":"1476593644","profile_pic_url":"https://instagram.fhel3-1.fna.fbcdn.net/vp/69d2a696339d3e64a6d6449cd36d10b9/5B151E06/t51.2885-19/s150x150/12139598_1056916654326731_785215976_a.jpg","username":"bbstylemiami"}},{"node":{"id":"5373895103","profile_pic_url":"https://instagram.fhel3-1.fna.fbcdn.net/vp/e4d101a7b7823862ff5ea09b9ca64db0/5B1C6515/t51.2885-19/s150x150/18443920_1839735143016586_6944955834094845952_a.jpg","username":"iambrokool"}},{"node":{"id":"345451524","profile_pic_url":"https://instagram.fhel3-1.fna.fbcdn.net/vp/0b4a2bceb2eaa1efd841874df94367e0/5B0B0207/t51.2885-19/11821658_877787485604500_693329869_a.jpg","username":"pleasefashionofficial"}}]},"edge_media_to_sponsor_user":{"edges":[]},"location":null,"viewer_has_liked":false,"viewer_has_saved":false,"viewer_has_saved_to_collection":false,"owner":{"id":"2096327952","profile_pic_url":"https://instagram.fhel3-1.fna.fbcdn.net/vp/b142448b7225a12c25a81c4e4f84a577/5B0BFE21/t51.2885-19/s150x150/11930847_519140961600089_515209800_a.jpg","username":"ropateando","blocked_by_viewer":false,"followed_by_viewer":false,"full_name":"RopaTeando","has_blocked_viewer":false,"is_private":false,"is_unpublished":false,"is_verified":false,"requested_by_viewer":false},"is_ad":false,"edge_web_media_to_related_media":{"edges":[]}}}}a 

As you see it contains pictures, title, user's info, user's mark, comments... and many other.

Answers 2

Based on your problem I would look at InstaPy. It has a simple API and it uses Selenium, a framework for browser automation, so you can avoid the API limits.

Install InstaPy:

$ git clone https://github.com/timgrossmann/InstaPy.git $ cd InstaPy $ pip install . # or $ python setup.py install 

Create a script:

# scraper.py from instapy import InstaPy  insta_username = '' insta_password = ''  # if you want to run this script on a server, # simply add nogui=True to the InstaPy() constructor session = InstaPy(username=insta_username, password=insta_password) session.login()  # set up all the settings session.set_upper_follower_count(limit=2500) session.set_do_comment(True, percentage=10) session.set_comments(['aMEIzing!', 'So much fun!!', 'Nicey!']) session.set_dont_include(['friend1', 'friend2', 'friend3']) session.set_dont_like(['pizza', 'girl'])  # do the actual liking session.like_by_tags(['natgeo', 'world'], amount=100)  # end the bot session session.end() 

Run the script:

$ python scraper.py 

Media:

If you don't feel comfortable working with Python, take a look at Puppeteer.

Puppeteer is a Node library which provides a high-level API to control headless Chrome or Chromium over the DevTools Protocol. It can also be configured to use full (non-headless) Chrome or Chromium.

Install Puppeteer:

npm i --save puppeteer 

Create a script:

// scraper.js const puppeteer = require('puppeteer');  (async () => {   const browser = await puppeteer.launch();   const page = await browser.newPage();   await page.goto('https://instagram.com');   // Take a screen shot     await page.screenshot({path: 'example.png'});    await browser.close(); })(); 

Run the script:

$ node scraper.js 

If you want to login, follow this guide.

Read More

Monday, June 5, 2017

Get user's recent media with account username instead of user ID

Leave a Comment

So I want to use the Instagram API to get a specific user's (NOT MY USER) recent media. Instagram has the following endpoint for doing so:

(GET) https://api.instagram.com/v1/users/{user-id}/media/recent/?access_token=ACCESS-TOKEN 

This is a problem because I do not have the user's ID (why would I, Instagram?). What I do have is the account username (as most people would), e.g. @thisisauser.

I've been reading the API docs and I can't find an endpoint that will give me the user ID for a specific account username. I mean, yes, there is:

(GET) https://api.instagram.com/v1/users/search?q=jack&access_token=ACCESS-TOKEN 

...but it doesn't do what I need it to do, which is to search for an exact match.

I've also checked out other threads on Stack Overflow and other websites. However, the alternative solutions offered are, at best, questionable.

The fact that this whole thing is an actual issue surprises me. I mean, SURELY there's a legitimate, Instagram-approved, precise and straightforward way of either:

  • obtaining a user's recent media by providing the account username (which is what people know you by... not a sequence of numbers) OR
  • obtaining a user's ID via an exact match search, with no chance of multiple possible results

FYI: I'm doing this server-side, using PHP and cURL.

Side note: If I have to make a separate request to the API in order to convert an account username to a user ID, that's just a waste of a request, one more for the hourly limit. Just an observation, in case any member of the Instagram team happens to see this.

3 Answers

Answers 1

I couldn't find anything in the API that gets a username's media. However, by using the search endpoint, you can come up with a solution to get a user's media.

Since you're using PHP cURL, you could do something like this:

//this is what was returned by cURL $response = /*what was returned by the API - see below*/  { "data": [{     "username": "jack",     "first_name": "Jack",     "profile_picture": "http://distillery.s3.amazonaws.com/profiles/profile_66_75sq.jpg",     "id": "66",     "last_name": "Dorsey" }, {     "username": "sammyjack",     "first_name": "Sammy",     "profile_picture": "http://distillery.s3.amazonaws.com/profiles/profile_29648_75sq_1294520029.jpg",     "id": "29648",     "last_name": "Jack" }, {     "username": "jacktiddy",     "first_name": "Jack",     "profile_picture": "http://distillery.s3.amazonaws.com/profiles/profile_13096_75sq_1286441317.jpg",     "id": "13096",     "last_name": "Tiddy" }] }  //username I am looking for $user = 'jack';  //filter array response to find exact username you are looking for $filter = array_filter($response,function($userdata) use ($user){     if($userdata['username'] == $user){         return $userdata;     }   });  //now use ID from filtered array to get media $url = 'https://api.instagram.com/v1/users/' . $filter['id'] . '/media/recent/?access_token=ACCESS-TOKEN'; 

Answers 2

You can get all of a user's information (including the id) by requesting this URL:

https://www.instagram.com/{username}/?__a=1 

For example, this gets you all of the information related to the account taylorswift:

https://www.instagram.com/taylorswift/?__a=1 

Answers 3

you can find user id !!!

like this :

<html> <head> <script src="jquery.js" type="text/javascript" ></script> <script type="text/javascript">   $(document).ready(function(){      $.ajax({             type: 'GET',             url: 'https://api.instagram.com/v1/users/self/?access_token=' + window.location.hash.substring(14),             dataType: 'jsonp'}).done(function(response){                  var userid = response.data.id;              });   }); </script> </head> <body> </body> </html> 

and save in to your data base .then when need find it and use that way to find recent media of user :

https://api.instagram.com/v1/users/{user-id}/media/recent/?access_token=ACCESS-TOKEN 

this way i think is beter. you can send a json with php too.

Read More

Sunday, May 14, 2017

Get a page info of Instagram

Leave a Comment

First of all I have found this url to get the public Instagram page info. https://www.instagram.com/facebook/?__a=1. Is this the correct way of accessing info or it can be broken any time in future? I have checked instagram api but I could not find client_credential support(actually I wanna access my Instagram public page from my server). Actually our server need to get and send this info to our native Android and IOS clients. What is the correct way to get page title/image/followers/following/description/posts(including likes and comments count)?

2 Answers

Answers 1

  • With out using instagram api,one can scrap instagram's website.Here is demo of scarping public profile picture of instagram's user.

  • I have created api in nodejs to fetch profile picture of instagram's user using cheerio module.And created frontend in angular2.As well as all this component deployed in Heroku Cloud.


Answers 2

Any hidden functionality is almost certain to be removed. You should always rely on the public APIs provided.

You should make use of the Instagram Users API, for your particular use case. https://www.instagram.com/developer/endpoints/users/

Ideal solution is, for every request from your Native Apps, you shouldn't be calling the instagram API, else you may be throttled. You must call instagram API on demand and probably cache the result for an hour or so.

Read More

Tuesday, October 11, 2016

Swift / Instagram API - how to auth with Instagram App

Leave a Comment

I need an AccessToken to have the User have granted access to his own Instagram Account within my App. I've registered everything within the Instagram Development Center.

Currently I'm using SimpleAuth to receive an AccessToken by Instagram.

So far everything is working well. I'm receiving the Token and am able to use it.

But when I wanted to login for the first time, I've noticed, that I had no idea what my password was. I always log in with Facebook or am already logged in. I don't want to have my users face the same issues and have them reset their Instagram password...

I have googled for a while now, without success. Is there a way to authenticate the User and receive an AccessToken using the Instagram App?

I already have added instagram to the LSApplicationQueriesSchemes at the info.plist and sending images to the Instagram App to post them there is working. So calling the app itself is not the issue.

This is my current code that opens a WebView within a UIViewController - but the User has to login with username and password.

enter image description here

func connectToInstagramFunc() {      let auth: NSMutableDictionary = ["client_id": INSTAGRAM_CLIENT_ID,                                      SimpleAuthRedirectURIKey: INSTAGRAM_REDIRECT_URI]      SimpleAuth.configuration()["instagram"] = auth      SimpleAuth.authorize("instagram") { (anyObject, error) in          if self.instagrammUsers.count > 0 {             self.deleteInstagram()         }          if anyObject != nil {              let token = String((anyObject.valueForKey("credentials")?.valueForKey("token"))!)             let uid =  String((anyObject.valueForKey("uid"))!)             let bio = String((anyObject.valueForKey("extra")?.valueForKey("raw_info")?.valueForKey("data")?.valueForKey("bio"))!)             let followed_by = String((anyObject.valueForKey("extra")?.valueForKey("raw_info")?.valueForKey("data")?.valueForKey("counts")?.valueForKey("followed_by"))!)             let follows = String((anyObject.valueForKey("extra")?.valueForKey("raw_info")?.valueForKey("data")?.valueForKey("counts")?.valueForKey("follows"))!)             let media = String((anyObject.valueForKey("extra")?.valueForKey("raw_info")?.valueForKey("data")?.valueForKey("counts")?.valueForKey("media"))!)             let username = String((anyObject.valueForKey("user_info")?.valueForKey("username"))!)             let image = String((anyObject.valueForKey("user_info")?.valueForKey("image"))!)              self.saveAccount(token, uid: uid, bio: bio, followed_by: followed_by, follows: follows, media: media, username: username, image: image)          } else {              let alert = UIAlertController(title: "Error!", message: "Please try again later!", preferredStyle: UIAlertControllerStyle.Alert)             alert.addAction(UIAlertAction(title: "OK", style: UIAlertActionStyle.Default, handler: nil))             self.presentViewController(alert, animated: true, completion: nil)         }            if error != nil {             SpeedLog.print("Error during SimpleAuth.authorize: \(error)")         }     } } 

What are my possibilities? Help is very appreciated.

1 Answers

Answers 1

No, you cannot use Instagram app to authenticate Instagram account at the moment.

However, web view seems to be a reasonable way to login especially in iOS 9 and above because it does not require user to switch between apps and having to tap on dialogs to switch app. The only pain is for the user to type username and password, but hopefully they only need to do that once (unless they change account).

Facebook has similar issue and choose to go with web view login as default way to authenticate.

For the people who are not signed into Facebook on Safari, they will only need to log into Facebook one time. After that, every future Facebook Login experience is fast and convenient with no extra steps. This means that as adoption of this flow increases over time, so does the quality of the experience people get. In contrast, the traditional fast-app-switch flow does not improve over time: The additional dialogs continue to appear in both directions for every new app that people log into.

https://developers.facebook.com/blog/post/2015/10/29/Facebook-Login-iOS9/

Read More

Sunday, September 11, 2016

Instagram OAuth Authentication - www.instagram.com redirected you too many times

Leave a Comment

I'm trying to use the server side explicit OAuth flow to allow a user authenticate with Instagram, so my application can retrieve media on their behalf.

I have configured my client on Instagram, which is in Sandbox mode, to redirect to https://localhost:44320/Admin/Instagram/OAuth.

I am redirecting the user to Instagram using this Url:

https://api.instagram.com/oauth/authorize?client_id=CLIENT_ID_IS_HERE&redirect_uri=https%3A%2F%2Flocalhost%3A44320%2FAdmin%2FInstagram%2FOAuth%3FweddingId%3D2&response_type=code&scope=public_content

My problem is that if the user is already authenticated, or successfully authenticates on Instagram, the redirect to my callback URL does not reach my endpoint and Chrome throws the "ERR_TOO_MANY_REDIRECTS" error. It also happens on IE Edge browser but it just hangs rather than giving an error.

From inspecting the network activity on Chrome, there is bouncing back and forth from:

https://www.instagram.com/oauth/authorize?client_id=...

to

https://www.instagram.com/integrity/checkpoint/?next=/oauth/authorize

and then back again.

I can't find any information on the Developer documentation and here on S/O from people experiencing the same thing.

I'd appreciate any help or suggestions as I'm stuck here!

0 Answers

Read More

Thursday, July 7, 2016

Any workaround for new Instagram API restriction with tags content

Leave a Comment

Hi i built a small module for my company's marketing team, which will fetch all the photos based on a hashtag (for example "nofilter")

So i have been using this URL with no problems until recently, Instagram decided to change their API authentication to OAuth:

https://api.instagram.com/v1/tags/nofilter/media/recent 

I followed the new guidelines, however my client is still in sandbox mode and the API call doesn't return anything anymore, all what it returns is this:

{"pagination": {"deprecation_warning": "next_max_id and min_id are deprecated for this endpoint; use min_tag_id and max_tag_id instead"}, "meta": {"code": 200}, "data": []} 

I did a bit of research and it seems like i will need to submit my application to go be reviewed to go live. However it doesn't seem possible, this is what i found from their submission guideline:

attached guideline screenshot

Is there any workaround for this? Any help is very well appreciated, thanks!

1 Answers

Answers 1

No, there is no workaround to this.

Read More

Thursday, June 30, 2016

Receiving “400 Bad Request” for /oauth/access_token

Leave a Comment

I have approved for public_content clientId. To get access token, I send a request to www.instagram.com:

GET /oauth/authorize?client_id=MyClientId&redirect_uri=MyRedirectURL&response_type=code&scope=likes+comments+public_content HTTP/1.1` 

After authentication, the browser redirects me to MyRedirectURL and I can get the code from the URL.

With this code I send a request to api.instagram.com:

/oauth/access_token HTTP/1.1 

client_id=MyClientId&client_secret=MyClientSecret&grant_type=authorization_code&redirect_uri=MyRedirectURL&code=CodeFromURL`

But sometimes I get response HTTP/1.1 400 Bad Request. This situation continues for a few hours, and sometimes for a day. It is interesting that the problem is very unstable. I may have two client apps that make identical requests, and one app will work fine, while the other will fail at the same time. Looks like it is a problem somewhere in the Instagram infrastructure.

2 Answers

Answers 1

Instagram is no longer supporting custom schemas for your callback urls. That was my problem, I changed it to https and the problem was solved.

Answers 2

This seems slightly relevant.

Also here they don't list any examples which is not http(s) :)

Read More

Tuesday, April 12, 2016

Similar to Tinder Instagram Connect

Leave a Comment

So I noticed that apps like Tinder can show Instagram connect of lets say, User A on everyone else's phones even without requiring other users to actually sign into instagram.

For example: User-A connects instagram and gets access token. Users-B, C, D... can see A's public & private pictures without even logging into instagram.

Is there a way to view another user's instagram without requiring access token - even private pictures by just using CLIENT_ID?

5 Answers

Answers 1

The previous answer is way too confusing... so let's handle it in a easy way, according to your question.

Let's start from understanding, what is access_token, in their API, in API requests alike:

api.instagram.com/v1/users/self/media/recent/?access_token=%@

Working through API, receiving this access_token still requires granting of access, and Authentication (see the manual on Receiving an access_token). As you can read there, all the possible options still require authenticated access.

Even though our access tokens do not specify an expiration time, your app should handle the case that either the user revokes access, or Instagram expires the token after some period of time. If the token is no longer valid, API responses will contain an “error_type=OAuthAccessTokenError”. In this case you will need to re-authenticate the user to obtain a new valid token. In other words: do not assume your access_token is valid forever.

This is standard authentication process in programming, with the access tokens, session identifiers, etc.

The world has been living with OAuth 2.0 Authorization Protocol for a long time, you are not the last guy who's concerned about it. If you are sleeping fine knowing about theoretical Session hijacking, then you shouldn't worry that much about potential security issues related to usage of APIs by access tokens.

It's secure enough. Aha, and another "small thing", I forgotten to mention: all requests to the Instagram API must be made over SSL (https:// not http://), which adds even more confidence.

To answer explicitly your question:

"is there a way to view another user's instagram without access token - even private pictures by just using CLIENT_ID?"

No, there's no possibility. Security token is the thing, which requires granting of access, and authentication. If it would allow this kind of access - this would be counted as security vulnerability. This is the basics of OAuth mechanism. If you need more understanding, you may read here, in a simple language, how OAuth is an authentication protocol works.

Answers 2

Let's not make confusion. Tinder user can opt-in for sharing Instagram photos. Tinder has no worldwide access to Instagram photos. I will answer you from the security perspective, as I have never tried setting up a Tinder account with Instagram connection to test the scenario for you.

Access token is embedded in Tinder app code, you may find it or not if you decompile the code, according on the level of obfuscation, and almost certainly if you use software such as mitmproxy. I won't discuss such a practice here.

So Tinder client is granted a token to access user's pictures.

Two cases:

  1. User opts in on Tinder/Instagram to access his private photos. The token is valid for those private photos. If you steal Tinder's token you can access any Tinder-Instagram user's private photos. That is not bad. User has chosen to share private photos to the world. But if an Instagram user is not a Tinder user be sure that you won't get anything
  2. Tinder will only fetch public photos. It will be just like anonymously browsing one's Instagram profile

Please mind that the token is valid for Tinder application, and is not user A's token. This is forbidden by security practices.

By associating your Tinder account with Instagram you grant Tinder's already-issued token to access your photos on behalf of you.

Summarizing:

  • Tinder client - Actor
  • Instagram - Resource server
  • User A's photos - Resource
  • User B (on Tinder, not on Instagram) - not an actor in the workflow
  • Token issued to Tinder: access to any (public or private??????) photos of users who have opted in to share Instagram photos on Tinder

Note: Tinder client may or may not use an Instagram-issued token. From a general security point-of-view, there are two implementation scenarios:

  1. Tinder client contacts Instagram server with a token that is issued to Tinder application and encoded in all clients
    • PRO: bandwidth is charged to user only
    • CON: exposing the token may grant one to access any Tinder-Instagram user photos without passing by Tinder
  2. Tinder app requests Tinder server to fetch photos from Instagram. Tinder client only authenticates with Tinder server
    • PRO: more secure design. Tinder-to-Instagram token never exposed. If a user leaves Tinder he can't access Instagram photos of other Tinder users
    • CON: Tinder server will be charged for the bandwidth needed to retrieve and distribute photos. This exposes Tinder to a potential violation of Instagram API ToS if they start caching the photos

Answers 3

Personally, I would avoid OAuth at all costs, it is too much work if you're just retrieving public data. Instead, I would write a curl script to grab the public Instagram data from the user's profile URL, and parse the HTML server-side, before ever considering OAuth.

Here's a quick mock-up example in PHP, using file_get_contents and DOMDocument:

 $doc = new DOMDocument();  $doc->preserveWhiteSpace = false;   //HTTP GET someone's profile  $doc->loadHTML(file_get_contents('https://www.instagram.com/profile_xxxxxx/'));   $selector = new DOMXPath($doc);   //Instagram stores image URL's in meta tag "og:image"  foreach($selector->query('//attribute::*[contains(., \'og:image\')]') as $e) {     //Store profile photo from DOMNode $e    $photourl = $e->getAttribute('content');     //Grab profile photo    file_get_contents($photourl);  } 

Answers 4

If you have an app which people grant access to Instagram, such as Tinder, then there are two simple methods you can use.

You can store the access_token and, so long as they are valid, pull their pictures at any time. In this case to display to other users on your app.

Otherwise you can copy images onto your own app. This is most useful for pulling display images, as you do not want to call the API every time you display their profile image, for example. If you downloaded ALL images, you would still need a valid user access_token to fetch new images.

If your app stores the access_tokens for all users whom granted you access then you can fetch all images at any time.

Answers 5

Let's consider that Instagram User Profiles pages like ISS page are available online without any authentication access:

https://www.instagram.com/iss/

Due to how Instagram works, only public images will be showed here (plus posts, followers, following).

So what you have to do is to get the page data. To do this you can use several solutions like PhantomJS that is as little as writing

var page = require('webpage').create(); page.open('https://www.instagram.com/iss/', function() {    var contents=page.contents; // here is the page contents    phantom.exit(); }); 

So, assumed you can execute this process on server-side you could provide those public profile images as a JSON object in a api response. Of course it's a little bit more complicated than this (i.e. you have to wait page resources to be loaded within PhantomJS, but at the end the web scraper can temporary save the page and turn it into a json structure, with <img/> source images, etc. ready to be showed in a app.

Read More

Wednesday, March 23, 2016

Instagram iOS API Error Domain=WebKitErrorDomain Code=102 “Frame load interrupted”

Leave a Comment

I am working on a project for iPhone where I have to take images from Instagram. I implemented the following API as mentioned on its developer site:

https://api.instagram.com/oauth/authorize/?client_id=CLIENT-ID&redirect_uri=REDIRECT-URI&response_type=code

When I hit this URL in my UIWebview I get the following error:

Error Domain=WebKitErrorDomain Code=102 "Frame load interrupted"

But when I hit the same URL in the device browser it works. But it modifies the URL to be:

https://www.instagram.com/accounts/login/?force_classic_login=&next=/oauth/authorize/?client_id=CLIENT_ID&redirect_uri=REDIRECT_URI&response_type=token&scope=SCOPE

I also tried to put this modified URL in my code. Then it works and asks me to log in. But when I log in I get this error.

{     "code": 400,     "error_type": "OAuthException",     "error_message": "You must include a valid client_id, response_type, and redirect_uri parameters" } 

I recently created a client ID and checked all parameters. So I'm not sure what the issue is. I googled it and found that UIWebView doesnt allow this. So I put this in didFinishLaunching in my AppDelegate class:

NSDictionary *dictionary = [[NSDictionary alloc] initWithObjectsAndKeys:@"Mozilla/5.0 (iPhone; CPU iPhone OS 5_0 like Mac OS X) AppleWebKit/534.46 (KHTML, like Gecko) Version/5.1 Mobile/9A334 Safari/7534.48.3", @"UserAgent", nil]; [[NSUserDefaults standardUserDefaults] registerDefaults:dictionary]; 

But this is also not working. Please advise for any solution regarding this.

0 Answers

Read More