siyuan-note/siyuan · error

renaming assets in encrypted notebooks is not supported

Error message

renaming assets in encrypted notebooks is not supported

What it means

Renaming an asset that lives inside an encrypted notebook is rejected. In encrypted notebooks the asset's on-disk filename participates in the AES-GCM AAD, so renaming would require re-encrypting/re-wrapping the ciphertext, which the current implementation does not support. The kernel returns this error early and leaves the asset unchanged.

Solutions

  1. Move the asset out of the encrypted notebook into a normal notebook's assets folder and rename it there
  2. Delete the asset and re-upload it with the desired filename
  3. Disable encryption for the notebook if encrypted assets are not required (understand the security trade-off), then rename
  4. Wait for/upgrade to a SiYuan version that supports re-wrapping encrypted asset names

Example fix

// before: rename inside encrypted notebook -> error
renameAsset('/data/notebooks/enc/assets/old.png', 'new.png')
// after: copy to a plaintext notebook, rename there
moveAssetToPlainNotebook('/data/notebooks/enc/assets/old.png'); renameAsset(newPlainPath, 'new.png')
Defensive patterns

Strategy: validation

Validate before calling

// check the asset is not in an encrypted notebook before renaming
const isEnc = await isEncryptedNotebookAsset(assetPath);
if (isEnc) throw new Error('rename not supported for encrypted-notebook assets');

Try / catch

try { await renameAsset(oldPath, newName) } catch (e) {
  if (e.message.includes('encrypted notebooks')) {
    offerMoveToPlainNotebookFlow();
  }
}

Prevention

When it happens

Trigger: Calling the asset rename API (model.RenameAsset) where GetAssetAbsPathInBox resolves the old path into an encrypted box and IsEncryptedAssetPath(absPath) is true.

Common situations: Users of encrypted-notebook workspaces trying to rename a misplaced asset via right-click rename in the assets panel; scripts or plugins calling the rename endpoint on encrypted-notebook assets.

Understand the failure class

Background: UnsupportedOperationException and "is not supported" errors: when a library deliberately refuses a call — this error's family across 30 libraries.

Related errors


AI-assisted analysis of siyuan-note/siyuan@9f775e8a12 (2026-09-19). Data as JSON: /api/errors/ba25f11a06d70b6f. Report an issue: GitHub.

Appendix: source

Thrown at kernel/model/assets.go:1654

	util.RemoveAssetText(relativePath)

	IncSync()

	indexHistoryDir(filepath.Base(historyDir), util.NewLute())
	cache.RemoveAsset(relativePath)
	return
}

func RenameAsset(oldPath, newName string) (newPath string, err error) {
	util.PushEndlessProgress(Conf.Language(110))
	defer util.PushClearProgress()

	oldCleanPath := AssetPathWithoutQuery(oldPath)

	// 加密笔记本的资源磁盘文件名参与 AAD,重命名需要重新封装密文,当前不支持。
	if absPath, absErr := GetAssetAbsPathInBox(oldPath, ""); absErr == nil {
		if IsEncryptedAssetPath(absPath) {
			err = errors.New("renaming assets in encrypted notebooks is not supported")
			return
		}
	}

	newName = strings.TrimSpace(newName)
	newName = util.FilterUploadFileName(newName)
	if path.Base(oldCleanPath) == newName {
		return
	}
	if "" == newName {
		return
	}

	if !gulu.File.IsValidFilename(newName) {
		err = errors.New(Conf.Language(151))
		return
	}

View on GitHub (pinned to 9f775e8a12)