{"record":{"id":"564a650b00862cc4","repo":"siyuan-note/siyuan","slug":"cli-does-not-support-encrypted-notebook-s","errorCode":null,"errorMessage":"CLI does not support encrypted notebook [%s]","messagePattern":"CLI does not support encrypted notebook \\[(.+?)\\]","errorType":"validation","errorClass":null,"httpStatus":null,"severity":"error","filePath":"kernel/cli/cmd/root.go","lineNumber":136,"sourceCode":"\t\t\treturn err\n\t\t}\n\t\treturn nil\n\t},\n}\n\n// rejectEncryptedNotebookCLI 拒绝 CLI 对加密笔记本及其块的操作。\n// 加密笔记本只能通过应用内专用流程解锁和操作，避免 CLI 进程成为明文或密文文件的旁路入口。\nfunc rejectEncryptedNotebookCLI(cmd *cobra.Command, args []string) error {\n\tif cmd == serveCmd {\n\t\treturn nil\n\t}\n\tif (cmd == notebookRandomIconCmd && !cmd.Flags().Changed(\"id\")) || cmd == exportDataCmd {\n\t\tboxID, err := firstEncryptedNotebookID()\n\t\tif err != nil {\n\t\t\treturn err\n\t\t}\n\t\tif boxID != \"\" {\n\t\t\treturn fmt.Errorf(\"CLI does not support encrypted notebook [%s]\", boxID)\n\t\t}\n\t}\n\n\tvar encryptedTarget string\n\tcheckID := func(id string) bool {\n\t\tif id == \"\" {\n\t\t\treturn false\n\t\t}\n\t\tif model.IsEncryptedBox(id) {\n\t\t\tencryptedTarget = id\n\t\t\treturn true\n\t\t}\n\t\tif bt := treenode.GetBlockTree(id); bt != nil && model.IsEncryptedBox(bt.BoxID) {\n\t\t\tencryptedTarget = bt.BoxID\n\t\t\treturn true\n\t\t}\n\t\treturn false\n\t}","sourceCodeStart":118,"sourceCodeEnd":154,"githubUrl":"https://github.com/siyuan-note/siyuan/blob/9f775e8a12daef8255556097396f9b2739078892/kernel/cli/cmd/root.go#L118-L154","documentation":"The CLI blocks operations that would act on encrypted notebooks, since encrypted notebook content can only be unlocked via the in-app flow and the CLI must not become a bypass for ciphertext/plaintext. For `notebook random-icon` without an explicit --id, or for `export data`, the guard enumerates all notebooks; if any encrypted notebook exists in the workspace, it refuses with the offending box ID.","triggerScenarios":"Running `SiYuan-Kernel notebook random-icon` (no --id flag) or `SiYuan-Kernel export data` in a workspace that contains at least one encrypted notebook (firstEncryptedNotebookID returns non-empty).","commonSituations":"Workspace mixes encrypted and normal notebooks; scripting bulk export on a machine whose notebooks were converted to encrypted notebooks; CI jobs operating on workspaces containing encrypted notebooks.","solutions":["For `notebook random-icon`, pass an explicit --id of a non-encrypted notebook so the guard does not scan all notebooks.","Unlock or open the encrypted notebook in the SiYuan app, or temporarily move the encrypted notebook out of the workspace before running the CLI command.","Use the in-app export flow for data export instead of the CLI when encrypted notebooks are present.","Skip/filter encrypted notebook IDs in any automation that drives the CLI."],"exampleFix":"// before\nSiYuan-Kernel notebook random-icon -w ~/SiYuan\n// after\nSiYuan-Kernel notebook random-icon -w ~/SiYuan --id 20240101120000-abcd123","handlingStrategy":"try-catch","validationCode":"// Go: pre-check for encrypted notebooks before calling notebook/export CLI commands\nfor _, box := range listNotebookIDs() {\n    if isEncryptedBox(box) { skipCommand = true }\n}","typeGuard":null,"tryCatchPattern":"if err := runKernelCLI(args); err != nil && strings.Contains(err.Error(), \"CLI does not support encrypted notebook\") {\n    // fall back to the in-app flow or skip the encrypted notebook\n}","preventionTips":["For `notebook random-icon`, always pass an explicit --id of a known plain notebook.","Inventory encrypted notebooks (they are reported in the error) and exclude them from CLI automation.","Route export of workspaces containing encrypted notebooks through the app UI."],"tags":["cli","encryption","notebook"],"backgroundTag":"unsupported-operation","analyzedSha":"9f775e8a12daef8255556097396f9b2739078892","analyzedAt":"2026-09-19T03:17:15.984Z","contentChangedAt":"2026-09-19T03:17:15.984Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}