On Windows, recover the Adobe ADEPT user key from an installed/activated
Adobe Digital Editions and use it automatically, so ADEPT EPUBs decrypt
with no --key argument. Ported from adobekey.py:
* Build the DPAPI entropy byte-for-byte: system-volume serial number,
CPUID leaf-0 vendor (EBX|EDX|ECX) and leaf-1 signature, and the ADE
username, packed as ">I12s3s13s".
* CryptUnprotectData (DPAPI) recovers the key-encryption-key from the
HKCU\Software\Adobe\Adept\Device "key" value, then each per-credential
privateLicenseKey under ...\Activation is AES-128-CBC decrypted and the
DER RSA key taken from byte 26 onward.
Decryption now lazily auto-extracts and retries when no supplied key fits,
and newly found keys are written back to the TOML config so later runs are
offline. Uses the `windows` (DPAPI/volume info) and `winreg` crates behind
cfg(windows); pure-Rust crypto unchanged.
Verified end-to-end on a real ADEPT EPUB: the key was extracted from the
local ADE and the book decrypted to a valid, DRM-free EPUB (rights.xml and
encryption.xml removed, content readable).
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>