magento2-38366: A fatal TypeError when the store cookie is an array without a valid code
Community fix magento2-38366 merged into magento/magento2 on 2026-07-09, not in a release yet; applies cleanly to 21 releases from 2.4.6 to 2.4.8-p1.
Fixes a fatal TypeError when the store cookie is an array without a valid code edited
- Pull request title
- Fatal error thrown on exception constructor when cookies store is an array
- Pull request
- magento/magento2#38366
- Issues
- #38365 human
- Author
- @andrewbess
- Merged
- 2026-07-09
- Fixed in
- no release yet
- Reported on
- 2.4.4-p6
- Categories
- —
- Components
- magento/module-store
Labels
- Area
- Framework
- Component
- Store
- Priority
- P2
- Severity
- —
- Reported on (labels)
- 2.4.4-p6
Issue
Title and steps come from the upstream issue and pull request.
Description
Steps to reproduce
$_COOKIE['store'] to be an array and not contain a valid store code.I don't know exactly how to set it this way but Magento code is written to handle that situation as you can see here:
https://github.com/magento/magento2/blob/2.4-develop/app/code/Magento/Store/Model/StoreResolver.php#L108
After seeing the fatal error popping up in our logs, I had to manually do :
$_COOKIE['store'] = ['test']; to replicate the bug.Expected result
Actual result
PHP message: PHP Fatal error: Uncaught TypeError: Exception::__construct(): Argument #1 ($message) must be of type string, Magento\\Framework\\Phrase given in /var/www/source/vendor/magento/module-store/Model/StoreResolver.php:110
Taken from the upstream issue.
Error signatures
- PHP message: PHP Fatal error: Uncaught TypeError: Exception::__construct(): Argument ($message) must be of type string, Magento\\Framework\\Phrase given
- Reason is the PHP InvalidArgumentException does not accept a \Magento\Framework\Phrase but only a string.
- - throw new \InvalidArgumentException(__('Invalid store parameter.'));
- + throw new \Magento\Framework\Exception\InvalidArgumentException(__('Invalid store parameter.'));
- + throw new \InvalidArgumentException('Invalid store parameter.');
Code match per tag
Each tag was checked with git apply --check against that tag's files. A clean match means the change applies; it is not a test result. Tags that already contain the fix are marked.
| Line | Code match per tag | Tests |
|---|---|---|
| 2.4.6 | 2.4.6 clean 2.4.6-p1 clean 2.4.6-p2 clean 2.4.6-p3 clean 2.4.6-p4 clean 2.4.6-p5 clean 2.4.6-p6 clean 2.4.6-p7 clean 2.4.6-p8 clean 2.4.6-p9 clean 2.4.6-p10 clean 2.4.6-p11 clean 2.4.6-p12 conflict 2.4.6-p13 conflict 2.4.6-p14 conflict 2.4.6-p15 conflict | 2.4.6: no test data 2.4.6-p1: no test data 2.4.6-p2: no test data 2.4.6-p3: no test data 2.4.6-p4: no test data 2.4.6-p5: no test data 2.4.6-p6: no test data 2.4.6-p7: no test data 2.4.6-p8: no test data 2.4.6-p9: no test data 2.4.6-p10: no test data 2.4.6-p11: no test data 2.4.6-p12: no test data 2.4.6-p13: no test data 2.4.6-p14: no test data 2.4.6-p15: no test data |
| 2.4.7 | 2.4.7 clean 2.4.7-p1 clean 2.4.7-p2 clean 2.4.7-p3 clean 2.4.7-p4 clean 2.4.7-p5 clean 2.4.7-p6 clean 2.4.7-p7 conflict 2.4.7-p8 conflict 2.4.7-p9 conflict 2.4.7-p10 conflict | 2.4.7: no test data 2.4.7-p1: no test data 2.4.7-p2: no test data 2.4.7-p3: no test data 2.4.7-p4: no test data 2.4.7-p5: no test data 2.4.7-p6: no test data 2.4.7-p7: no test data 2.4.7-p8: no test data 2.4.7-p9: no test data 2.4.7-p10: no test data |
| 2.4.8 | 2.4.8 clean 2.4.8-p1 clean 2.4.8-p2 conflict 2.4.8-p3 conflict 2.4.8-p4 conflict 2.4.8-p5 conflict | 2.4.8: no test data 2.4.8-p1: no test data 2.4.8-p2: no test data 2.4.8-p3: no test data 2.4.8-p4: no test data 2.4.8-p5: no test data |
| 2.4.9 | 2.4.9 conflict | 2.4.9: no test data |
Triage
Model @cf/cloudflare/clef. Probability this is a bug fix: 97.7%. Probability it is security relevant: 36.0%.
Show the model's answers and probabilities
| Question | Answer | Probabilities | Confidence |
|---|---|---|---|
| Change kind | bugfix | bugfix 96.7%, refactor 1.3%, tests_only 0.7%, feature 0.5%, dependency 0.4%, docs_only 0.4% | 92.1% |
| Area | framework | framework 45.9%, other 20.5%, frontend 13.3% | 17.6% |
| Reported version | 2.4.4-p6 | 2.4.4-p6 60.8%, 2.4.4 3.9%, 2.4.6-p1 0.7% | 36.5% |
| Scope | 0.36 of 2 | 0 68.8%, 1 26.4%, 2 4.8% | 31.7% |
| Risk | 0.26 of 2 | 0 79.1%, 1 16.0%, 2 4.9% | 48.1% |
| Worth backporting | 1.65 of 2 | 2 71.9%, 1 21.1%, 0 7.0% | 35.0% |
Download
For cweagans/composer-patches, choose a version below and download the bundle. Copy its magento2-38366/ folder into patches/composer/, merge composer.patches.json into composer.json, then run composer install. Test files are always removed; paths are relative to each package root, using the default -p1 level.
Bundle README (what the ZIP ships)
# magento2-38366 Community fix merged upstream into magento/magento2, adapted by magento.watch. This is not a patch published by Adobe. Pull request: https://github.com/magento/magento2/pull/38366 Issue: https://github.com/magento/magento2/issues/38365 Author: @andrewbess Source commit: 7ad3f8ec15d46f42783274b6d2eee13fd0a2dcdf Modifications: test files and documentation removed, paths rewritten relative to each Composer package. Licence: OSL-3.0 / AFL-3.0, as the original Magento Open Source code. Maintainer: Łukasz Bajsarowicz (@lbajsarowicz)
Licence: Magento Open Source code under OSL-3.0 and AFL-3.0. The bundle carries the original author, source commit and the list of modifications.
