laravel/framework · error · InvalidArgumentException
The given password does not match the current password.
Error message
The given password does not match the current password.
What it means
Thrown by SessionGuard::rehashUserPasswordForDeviceLogout() when the password supplied for 'logout other devices' (AuthenticateSession middleware) does not match the currently authenticated user's stored hash. This guards the device-logout flow that rehashes the password to invalidate other sessions.
Solutions
- Have the user re-enter their current password correctly on the logout-other-devices form.
- Confirm the user model's getAuthPassword() returns the bcrypt/argon2 hash from the DB.
- Verify the configured hash driver matches the algorithm used to store the password.
- Catch InvalidArgumentException in the controller and show a validation error to the user.
Example fix
// before
request()->validate(['password' => 'required|string']);
Auth::logoutOtherDevices(request('password')); // throws if mismatch
// after — validate first, handle the failure gracefully
request()->validate(['password' => 'required|string']);
try {
Auth::logoutOtherDevices(request('password'));
} catch (\InvalidArgumentException $e) {
throw ValidationException::withMessages(['password' => __('The provided password is incorrect.')]);
} Defensive patterns
Strategy: try-catch
Validate before calling
// PHP — verify the password before calling logoutOtherDevices
if (! \Illuminate\Support\Facades\Hash::check(request('password'), Auth::user()->getAuthPassword())) {
throw \Illuminate\Validation\ValidationException::withMessages(['password' => __('The provided password is incorrect.')]);
}
Auth::logoutOtherDevices(request('password')); Type guard
function passwordMatchesCurrent(string $password): bool {
return \Illuminate\Support\Facades\Hash::check($password, Auth::user()->getAuthPassword());
} Try / catch
try {
Auth::logoutOtherDevices(request('password'));
} catch (\InvalidArgumentException $e) {
throw \Illuminate\Validation\ValidationException::withMessages(['password' => __('The provided password does not match our records.')]);
} Prevention
- Validate the current password with Hash::check before the device-logout call.
- Ensure the password column uses the configured hasher.
- Surface a friendly validation error rather than letting the InvalidArgumentException propagate.
When it happens
Trigger: Calling the logout-other-devices flow (route auth.logout.other.devices with 'auth.session' middleware) where the posted 'password' fails Hash::check against $user->getAuthPassword().
Common situations: User mistypes their current password on the 'logout other devices' form; the password was recently changed and the session still holds a stale user; the password column is not hashed with the configured hasher (e.g. md5 legacy); AuthenticateSession middleware used with a non-default hasher.
Related errors
- Cookie jar has not been set.
- Auth driver [ ] for guard [ ] is not defined.
- Auth guard [ ] is not defined.
- Authentication user provider
- CSRF token mismatch.
AI-assisted analysis of laravel/framework@e0f6eb3518 (2026-08-11).
Data as JSON: /api/errors/ef55a24d33ab9159.
Report an issue: GitHub.
Appendix: source
Thrown at src/Illuminate/Auth/SessionGuard.php:771
$this->fireOtherDeviceLogoutEvent($this->user());
return $result;
}
/**
* Rehash the current user's password for logging out other devices via AuthenticateSession.
*
* @param string $password
* @return \Illuminate\Contracts\Auth\Authenticatable|null
*
* @throws \InvalidArgumentException
*/
protected function rehashUserPasswordForDeviceLogout(#[\SensitiveParameter] $password)
{
$user = $this->user();
if (! Hash::check($password, $user->getAuthPassword())) {
throw new InvalidArgumentException('The given password does not match the current password.');
}
$this->provider->rehashPasswordIfRequired(
$user, ['password' => $password], force: true
);
}
/**
* Register an authentication attempt event listener.
*
* @param mixed $callback
* @return void
*/
public function attempting($callback)
{
$this->events?->listen(Events\Attempting::class, $callback);
}
View on GitHub (pinned to e0f6eb3518)