{"record":{"id":"76075dd8ec67e636","repo":"laravel/framework","slug":"cookie-jar-has-not-been-set","errorCode":null,"errorMessage":"Cookie jar has not been set.","messagePattern":"Cookie jar has not been set\\.","errorType":"exception","errorClass":"RuntimeException","httpStatus":null,"severity":"error","filePath":"src/Illuminate/Auth/SessionGuard.php","lineNumber":932,"sourceCode":"     */\n    public function setRememberDuration($minutes)\n    {\n        $this->rememberDuration = $minutes;\n\n        return $this;\n    }\n\n    /**\n     * Get the cookie creator instance used by the guard.\n     *\n     * @return \\Illuminate\\Contracts\\Cookie\\QueueingFactory\n     *\n     * @throws \\RuntimeException\n     */\n    public function getCookieJar()\n    {\n        if (! isset($this->cookie)) {\n            throw new RuntimeException('Cookie jar has not been set.');\n        }\n\n        return $this->cookie;\n    }\n\n    /**\n     * Set the cookie creator instance used by the guard.\n     *\n     * @param  \\Illuminate\\Contracts\\Cookie\\QueueingFactory  $cookie\n     * @return void\n     */\n    public function setCookieJar(CookieJar $cookie)\n    {\n        $this->cookie = $cookie;\n    }\n\n    /**\n     * Get the event dispatcher instance.","sourceCodeStart":914,"sourceCodeEnd":950,"githubUrl":"https://github.com/laravel/framework/blob/e0f6eb3518ac29fbbca8529e97d0df7fc9f24481/src/Illuminate/Auth/SessionGuard.php#L914-L950","documentation":"Thrown by SessionGuard::getCookieJar() when $this->cookie has never been assigned via setCookieJar(). The session guard queues remember-me and re-login cookies through a CookieJar; if the jar was not injected (typically by the Service Provider), any operation needing it fails.","triggerScenarios":"Using the SessionGuard outside the normal HTTP kernel wiring (e.g. in a queue worker, console command, or test) where the AuthServiceProvider's call to setCookieJar() did not run, and then invoking a path that needs cookies (login with remember, device logout with cookies).","commonSituations":"Instantiating SessionGuard manually in a test without calling setCookieJar(); running auth flows inside a queued job/artisan command that bypasses the cookie middleware; a custom service provider that overrides the session guard creation and forgets to inject the jar.","solutions":["Use the standard HTTP kernel/auth service provider so setCookieJar() is wired automatically.","If constructing the guard manually, call $guard->setCookieJar(app(CookieJar::class)).","Avoid triggering cookie-dependent auth operations (remember me, device logout) in non-HTTP contexts.","In tests, resolve the guard from the container rather than new-ing it directly."],"exampleFix":"// before — manual guard in a test, no cookie jar\n$guard = new SessionGuard('web', $provider, session());\n$guard->login($user, true); // RuntimeException: Cookie jar has not been set.\n\n// after — inject the jar\n$guard = new SessionGuard('web', $provider, request()->session());\n$guard->setCookieJar(app(\\Illuminate\\Cookie\\CookieJar::class));\n$guard->login($user, true);\n// or simply resolve from the container: $guard = Auth::guard('web');","handlingStrategy":"validation","validationCode":"// PHP — resolve the guard from the container (jar is wired automatically)\n$guard = Auth::guard('web'); // do not `new SessionGuard(...)` directly\n// If you must construct manually:\nif (! isset($guard->getCookieJar())) { /* only call after setCookieJar */ }","typeGuard":"// Heuristic guard for non-HTTP contexts: skip cookie-dependent operations\nfunction guardHasCookieJar(\\Illuminate\\Auth\\SessionGuard $g): bool {\n    try { $g->getCookieJar(); return true; }\n    catch (\\RuntimeException) { return false; }\n}","tryCatchPattern":"try {\n    $guard->login($user, $remember);\n} catch (\\RuntimeException $e) {\n    if (str_contains($e->getMessage(), 'Cookie jar')) {\n        $guard->setCookieJar(app(\\Illuminate\\Cookie\\CookieJar::class));\n        $guard->login($user, $remember);\n    } else throw $e;\n}","preventionTips":["Resolve SessionGuard from the container, not via new.","Inject the CookieJar when constructing the guard manually.","Avoid remember-me/device-logout flows in non-HTTP (queue/console) contexts."],"tags":["authentication","session","cookies","laravel"],"backgroundTag":null,"analyzedSha":"e0f6eb3518ac29fbbca8529e97d0df7fc9f24481","analyzedAt":"2026-08-11T20:52:37.562Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}