{"record":{"id":"ef55a24d33ab9159","repo":"laravel/framework","slug":"the-given-password-does-not-match-the-current-pass","errorCode":null,"errorMessage":"The given password does not match the current password.","messagePattern":"The given password does not match the current password\\.","errorType":"exception","errorClass":"InvalidArgumentException","httpStatus":null,"severity":"error","filePath":"src/Illuminate/Auth/SessionGuard.php","lineNumber":771,"sourceCode":"        $this->fireOtherDeviceLogoutEvent($this->user());\n\n        return $result;\n    }\n\n    /**\n     * Rehash the current user's password for logging out other devices via AuthenticateSession.\n     *\n     * @param  string  $password\n     * @return \\Illuminate\\Contracts\\Auth\\Authenticatable|null\n     *\n     * @throws \\InvalidArgumentException\n     */\n    protected function rehashUserPasswordForDeviceLogout(#[\\SensitiveParameter] $password)\n    {\n        $user = $this->user();\n\n        if (! Hash::check($password, $user->getAuthPassword())) {\n            throw new InvalidArgumentException('The given password does not match the current password.');\n        }\n\n        $this->provider->rehashPasswordIfRequired(\n            $user, ['password' => $password], force: true\n        );\n    }\n\n    /**\n     * Register an authentication attempt event listener.\n     *\n     * @param  mixed  $callback\n     * @return void\n     */\n    public function attempting($callback)\n    {\n        $this->events?->listen(Events\\Attempting::class, $callback);\n    }\n","sourceCodeStart":753,"sourceCodeEnd":789,"githubUrl":"https://github.com/laravel/framework/blob/e0f6eb3518ac29fbbca8529e97d0df7fc9f24481/src/Illuminate/Auth/SessionGuard.php#L753-L789","documentation":"Thrown by SessionGuard::rehashUserPasswordForDeviceLogout() when the password supplied for 'logout other devices' (AuthenticateSession middleware) does not match the currently authenticated user's stored hash. This guards the device-logout flow that rehashes the password to invalidate other sessions.","triggerScenarios":"Calling the logout-other-devices flow (route auth.logout.other.devices with 'auth.session' middleware) where the posted 'password' fails Hash::check against $user->getAuthPassword().","commonSituations":"User mistypes their current password on the 'logout other devices' form; the password was recently changed and the session still holds a stale user; the password column is not hashed with the configured hasher (e.g. md5 legacy); AuthenticateSession middleware used with a non-default hasher.","solutions":["Have the user re-enter their current password correctly on the logout-other-devices form.","Confirm the user model's getAuthPassword() returns the bcrypt/argon2 hash from the DB.","Verify the configured hash driver matches the algorithm used to store the password.","Catch InvalidArgumentException in the controller and show a validation error to the user."],"exampleFix":"// before\nrequest()->validate(['password' => 'required|string']);\nAuth::logoutOtherDevices(request('password')); // throws if mismatch\n\n// after — validate first, handle the failure gracefully\nrequest()->validate(['password' => 'required|string']);\ntry {\n    Auth::logoutOtherDevices(request('password'));\n} catch (\\InvalidArgumentException $e) {\n    throw ValidationException::withMessages(['password' => __('The provided password is incorrect.')]);\n}","handlingStrategy":"try-catch","validationCode":"// PHP — verify the password before calling logoutOtherDevices\nif (! \\Illuminate\\Support\\Facades\\Hash::check(request('password'), Auth::user()->getAuthPassword())) {\n    throw \\Illuminate\\Validation\\ValidationException::withMessages(['password' => __('The provided password is incorrect.')]);\n}\nAuth::logoutOtherDevices(request('password'));","typeGuard":"function passwordMatchesCurrent(string $password): bool {\n    return \\Illuminate\\Support\\Facades\\Hash::check($password, Auth::user()->getAuthPassword());\n}","tryCatchPattern":"try {\n    Auth::logoutOtherDevices(request('password'));\n} catch (\\InvalidArgumentException $e) {\n    throw \\Illuminate\\Validation\\ValidationException::withMessages(['password' => __('The provided password does not match our records.')]);\n}","preventionTips":["Validate the current password with Hash::check before the device-logout call.","Ensure the password column uses the configured hasher.","Surface a friendly validation error rather than letting the InvalidArgumentException propagate."],"tags":["authentication","session","password","laravel"],"backgroundTag":null,"analyzedSha":"e0f6eb3518ac29fbbca8529e97d0df7fc9f24481","analyzedAt":"2026-08-11T20:52:37.562Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}