{"record":{"id":"f1e51384f08e8a4e","repo":"laravel/framework","slug":"user-must-implement-canresetpassword-interface","errorCode":null,"errorMessage":"User must implement CanResetPassword interface.","messagePattern":"User must implement CanResetPassword interface\\.","errorType":"exception","errorClass":"UnexpectedValueException","httpStatus":null,"severity":"error","filePath":"src/Illuminate/Auth/Passwords/PasswordBroker.php","lineNumber":183,"sourceCode":"        return $user;\n    }\n\n    /**\n     * Get the user for the given credentials.\n     *\n     * @param  array  $credentials\n     * @return \\Illuminate\\Contracts\\Auth\\CanResetPassword|null\n     *\n     * @throws \\UnexpectedValueException\n     */\n    public function getUser(#[\\SensitiveParameter] array $credentials)\n    {\n        $credentials = Arr::except($credentials, ['token']);\n\n        $user = $this->users->retrieveByCredentials($credentials);\n\n        if ($user && ! $user instanceof CanResetPasswordContract) {\n            throw new UnexpectedValueException('User must implement CanResetPassword interface.');\n        }\n\n        return $user;\n    }\n\n    /**\n     * Create a new password reset token for the given user.\n     *\n     * @param  \\Illuminate\\Contracts\\Auth\\CanResetPassword  $user\n     * @return string\n     */\n    public function createToken(CanResetPasswordContract $user)\n    {\n        return $this->tokens->create($user);\n    }\n\n    /**\n     * Delete password reset tokens of the given user.","sourceCodeStart":165,"sourceCodeEnd":201,"githubUrl":"https://github.com/laravel/framework/blob/e0f6eb3518ac29fbbca8529e97d0df7fc9f24481/src/Illuminate/Auth/Passwords/PasswordBroker.php#L165-L201","documentation":"Thrown by PasswordBroker::getUser() when the user retrieved by credentials does not implement the Illuminate\\Contracts\\Auth\\CanResetPassword contract. The password reset broker calls getEmailForPasswordReset() and getRememberTokenName()-style methods on the user, so the contract is required for the reset flow.","triggerScenarios":"Running a password reset (Password::sendResetLink / Password::reset) where the resolved user model class does not implement CanResetPassword (typically by failing to extend Illuminate\\Foundation\\Auth\\User or Illuminate\\Database\\Eloquent\\Model + the trait).","commonSituations":"A custom User model that extends a bare Eloquent\\Model without the Illuminate\\Auth\\Passwords\\CanResetPassword trait and the CanResetPassword contract; swapping the auth provider to return a different DTO/user class that lacks the contract; legacy upgrades where the contract was added in a newer version.","solutions":["Make the User model implement Illuminate\\Contracts\\Auth\\CanResetPassword and use the Illuminate\\Auth\\Passwords\\CanResetPassword trait.","Extend Illuminate\\Foundation\\Auth\\User (which already wires the trait and contract).","Ensure the auth provider's 'model' points at a class that satisfies the contract.","If using a non-Eloquent user, implement getEmailForPasswordReset() and sendPasswordResetNotification() manually."],"exampleFix":"// before\nuse Illuminate\\Database\\Eloquent\\Model;\nclass Member extends Model {} // no CanResetPassword\n\n// after\nuse Illuminate\\Database\\Eloquent\\Model;\nuse Illuminate\\Contracts\\Auth\\CanResetPassword as CanResetPasswordContract;\nuse Illuminate\\Auth\\Passwords\\CanResetPassword;\nclass Member extends Model implements CanResetPasswordContract\n{\n    use CanResetPassword;\n}","handlingStrategy":"type-guard","validationCode":"// PHP — assert the user model satisfies the contract before reset flow\nif (! is_subclass_of($userModel, \\Illuminate\\Contracts\\Auth\\CanResetPassword::class)) {\n    throw new \\RuntimeException(\"{$userModel} must implement CanResetPassword to support password reset.\");\n}\nPassword::broker()->sendResetLink($credentials);","typeGuard":"function userSupportsReset(string $modelClass): bool {\n    return is_subclass_of($modelClass, \\Illuminate\\Contracts\\Auth\\CanResetPassword::class);\n}","tryCatchPattern":"try {\n    Password::broker()->sendResetLink($credentials);\n} catch (\\UnexpectedValueException $e) {\n    report('User model does not implement CanResetPassword: '.$e->getMessage());\n    return back()->withErrors(['email' => 'Password reset is not available for this account type.']);\n}","preventionTips":["Extend Illuminate\\Foundation\\Auth\\User or apply the CanResetPassword trait + contract.","Keep the provider 'model' pointed at a contract-compliant class.","Add a static-analysis rule (PHPStan) for the CanResetPassword contract."],"tags":["authentication","password-reset","laravel","contracts"],"backgroundTag":null,"analyzedSha":"e0f6eb3518ac29fbbca8529e97d0df7fc9f24481","analyzedAt":"2026-08-11T20:52:37.562Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}