I can reproduce the issue on Safari for Mac, so it does not seem to be a problem with the Instagram in-app browser only.
One thing I notice is this error:
Refused to connect to wss://garageratz.com/live/websocket?_csrf_token=...
...because it does not appear in the connect-src directive of the Content Security Policy.
I think the problem is that Phoenix LiveView JS fails to connect to the channel due to a CSP violation, and therefore triggers a reload after a timeout. The violation seems to be that your Content-Security-Policy header contains connect-src 'self';. According to MDN:
‘self’ Refers to the origin from which the protected document is being served, including the same URL scheme and port number.
So wss://garageratz.com/... is disallowed, because it uses a different URL scheme than https://garageratz.com.
Note that Chrome is more permissive than Safari when it comes to CSP, which explains why the issue does not occur on Chrome. See this issue for details.


















