laravel/framework · error · InvalidArgumentException

The given password does not match the current password.

Error message

The given password does not match the current password.

What it means

Thrown by SessionGuard::rehashUserPasswordForDeviceLogout() when the password supplied for 'logout other devices' (AuthenticateSession middleware) does not match the currently authenticated user's stored hash. This guards the device-logout flow that rehashes the password to invalidate other sessions.

Solutions

  1. Have the user re-enter their current password correctly on the logout-other-devices form.
  2. Confirm the user model's getAuthPassword() returns the bcrypt/argon2 hash from the DB.
  3. Verify the configured hash driver matches the algorithm used to store the password.
  4. Catch InvalidArgumentException in the controller and show a validation error to the user.

Example fix

// before
request()->validate(['password' => 'required|string']);
Auth::logoutOtherDevices(request('password')); // throws if mismatch

// after — validate first, handle the failure gracefully
request()->validate(['password' => 'required|string']);
try {
    Auth::logoutOtherDevices(request('password'));
} catch (\InvalidArgumentException $e) {
    throw ValidationException::withMessages(['password' => __('The provided password is incorrect.')]);
}
Defensive patterns

Strategy: try-catch

Validate before calling

// PHP — verify the password before calling logoutOtherDevices
if (! \Illuminate\Support\Facades\Hash::check(request('password'), Auth::user()->getAuthPassword())) {
    throw \Illuminate\Validation\ValidationException::withMessages(['password' => __('The provided password is incorrect.')]);
}
Auth::logoutOtherDevices(request('password'));

Type guard

function passwordMatchesCurrent(string $password): bool {
    return \Illuminate\Support\Facades\Hash::check($password, Auth::user()->getAuthPassword());
}

Try / catch

try {
    Auth::logoutOtherDevices(request('password'));
} catch (\InvalidArgumentException $e) {
    throw \Illuminate\Validation\ValidationException::withMessages(['password' => __('The provided password does not match our records.')]);
}

Prevention

When it happens

Trigger: Calling the logout-other-devices flow (route auth.logout.other.devices with 'auth.session' middleware) where the posted 'password' fails Hash::check against $user->getAuthPassword().

Common situations: User mistypes their current password on the 'logout other devices' form; the password was recently changed and the session still holds a stale user; the password column is not hashed with the configured hasher (e.g. md5 legacy); AuthenticateSession middleware used with a non-default hasher.

Related errors


AI-assisted analysis of laravel/framework@e0f6eb3518 (2026-08-11). Data as JSON: /api/errors/ef55a24d33ab9159. Report an issue: GitHub.

Appendix: source

Thrown at src/Illuminate/Auth/SessionGuard.php:771

        $this->fireOtherDeviceLogoutEvent($this->user());

        return $result;
    }

    /**
     * Rehash the current user's password for logging out other devices via AuthenticateSession.
     *
     * @param  string  $password
     * @return \Illuminate\Contracts\Auth\Authenticatable|null
     *
     * @throws \InvalidArgumentException
     */
    protected function rehashUserPasswordForDeviceLogout(#[\SensitiveParameter] $password)
    {
        $user = $this->user();

        if (! Hash::check($password, $user->getAuthPassword())) {
            throw new InvalidArgumentException('The given password does not match the current password.');
        }

        $this->provider->rehashPasswordIfRequired(
            $user, ['password' => $password], force: true
        );
    }

    /**
     * Register an authentication attempt event listener.
     *
     * @param  mixed  $callback
     * @return void
     */
    public function attempting($callback)
    {
        $this->events?->listen(Events\Attempting::class, $callback);
    }

View on GitHub (pinned to e0f6eb3518)