{"record":{"id":"d4a49597ab7981b6","repo":"siyuan-note/siyuan","slug":"imported-notebook-s-contains-encrypted-payload","errorCode":null,"errorMessage":"imported notebook [%s] contains encrypted payload without identity","messagePattern":"imported notebook \\[(.+?)\\] contains encrypted payload without identity","errorType":"exception","errorClass":null,"httpStatus":null,"severity":"error","filePath":"kernel/model/import.go","lineNumber":1373,"sourceCode":"\t\t\t\tboxCrypt = boxConf.BoxCrypt\n\t\t\t} else {\n\t\t\t\tboxCrypt = backup\n\t\t\t}\n\t\t\tif boxCrypt == nil {\n\t\t\t\treturn nil, fmt.Errorf(\"encrypted notebook [%s] has no valid identity\", boxID)\n\t\t\t}\n\t\t} else if boxConf != nil && backup != nil {\n\t\t\treturn nil, fmt.Errorf(\"notebook [%s] has conflicting normal and encrypted identities\", boxID)\n\t\t} else if backup != nil {\n\t\t\tboxCrypt = backup\n\t\t}\n\n\t\tpayloadFound, payloadErr := hasEncryptedNotebookPayloadAtPath(boxDir)\n\t\tif payloadErr != nil {\n\t\t\treturn nil, fmt.Errorf(\"inspect imported notebook [%s] failed: %w\", boxID, payloadErr)\n\t\t}\n\t\tif boxCrypt == nil && payloadFound {\n\t\t\treturn nil, fmt.Errorf(\"imported notebook [%s] contains encrypted payload without identity\", boxID)\n\t\t}\n\t\tif boxCrypt == nil {\n\t\t\tcontinue\n\t\t}\n\n\t\tif err = validateBoxEncryption(boxCrypt); err != nil {\n\t\t\treturn nil, fmt.Errorf(\"invalid imported notebook identity [%s]: %w\", boxID, err)\n\t\t}\n\t\tif filelock.IsExist(filepath.Join(util.DataDir, boxID)) && IsEncryptedBox(boxID) {\n\t\t\treturn nil, fmt.Errorf(\"refuse to overwrite existing encrypted notebook [%s]\", boxID)\n\t\t}\n\t\tencryptedBoxIDs = append(encryptedBoxIDs, boxID)\n\t}\n\treturn encryptedBoxIDs, nil\n}\n\nfunc ImportData(zipPath string) (err error) {\n\tutil.PushEndlessProgress(Conf.Language(73))","sourceCodeStart":1355,"sourceCodeEnd":1391,"githubUrl":"https://github.com/siyuan-note/siyuan/blob/9f775e8a12daef8255556097396f9b2739078892/kernel/model/import.go#L1355-L1391","documentation":"ImportData validates each notebook inside an imported data.zip before merging it. If a notebook's payload on disk is encrypted (hasEncryptedNotebookPayloadAtPath returns true) but no valid encryption identity (BoxEncryption salt/verifier config or crypto backup file) could be resolved for that notebook, the import is aborted. Without the identity the kernel cannot authenticate or decrypt the payload, so importing it would produce an unreadable notebook.","triggerScenarios":"Calling ImportData (or the /api/import/importData endpoint) with a data.zip whose notebook directory contains encrypted .sy payloads, while the notebook's .siyuan/conf.json lacks boxConf.Encrypted/BoxCrypt and no notebook crypto backup file exists inside the archive.","commonSituations":"Hand-assembled or partially edited data.zip backups where the .siyuan metadata directory was stripped; archives produced by older tooling before the crypto backup file existed; users manually copying notebook data folders without the hidden .siyuan directory.","solutions":["Re-export the data.zip from the original SiYuan workspace so the notebook's .siyuan/conf.json and crypto backup file are included","Verify the archive contains the hidden .siyuan directory for each notebook and that conf.json has \"encrypted\": true plus a valid boxCrypt object","If you intentionally do not want encryption, remove the encrypted payload (decrypt the notebook in the source workspace first) and re-export","Import into the original workspace where the notebook identity is already configured, rather than a fresh workspace"],"exampleFix":"// before: zip built manually without .siyuan metadata\n// data.zip\n//   notebook-20240102150405-xxx/*.sy   (encrypted payload, no .siyuan/)\n// after: export via SiYuan 'Export data.zip' so metadata ships\n// data.zip\n//   notebook-20240102150405-xxx/*.sy\n//   notebook-20240102150405-xxx/.siyuan/conf.json  (encrypted:true, boxCrypt:{...})\n//   notebook-20240102150405-xxx/.siyuan/<crypto backup file>","handlingStrategy":"validation","validationCode":"// Go: before calling ImportData, inspect the archive for encrypted notebooks missing identity\nfor _, boxID := range listNotebookDirsInZip(zipPath) {\n    hasPayload := zipContainsEncryptedPayload(zipPath, boxID) // .siyuan payload markers present\n    hasIdentity := zipContainsFile(zipPath, boxID+\"/.siyuan/\") && confHasBoxCrypt(zipPath, boxID)\n    if hasPayload && !hasIdentity {\n        return fmt.Errorf(\"archive notebook %s lacks encryption identity; re-export from source workspace\", boxID)\n    }\n}","typeGuard":null,"tryCatchPattern":null,"preventionTips":["Always export data.zip via SiYuan's built-in export so .siyuan metadata is included","Never strip hidden .siyuan directories when repacking archives","Before importing into a fresh workspace, confirm encrypted notebooks ship their crypto backup files","Document that encrypted notebooks cannot be migrated by manually copying payload files only"],"tags":["import","encryption","notebook","data-integrity"],"backgroundTag":"missing-credentials","analyzedSha":"9f775e8a12daef8255556097396f9b2739078892","analyzedAt":"2026-09-19T03:17:15.984Z","contentChangedAt":"2026-09-19T03:17:15.984Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}