core: Properly parent QObject-derived attributes
[quassel.git] / src / core / core.cpp
index 1df55da..b103b42 100644 (file)
@@ -1,11 +1,11 @@
 /***************************************************************************
- *   Copyright (C) 2005-07 by The Quassel IRC Development Team             *
+ *   Copyright (C) 2005-2018 by the Quassel Project                        *
  *   devel@quassel-irc.org                                                 *
  *                                                                         *
  *   This program is free software; you can redistribute it and/or modify  *
  *   it under the terms of the GNU General Public License as published by  *
  *   the Free Software Foundation; either version 2 of the License, or     *
- *   (at your option) any later version.                                   *
+ *   (at your option) version 3.                                           *
  *                                                                         *
  *   This program is distributed in the hope that it will be useful,       *
  *   but WITHOUT ANY WARRANTY; without even the implied warranty of        *
  *   You should have received a copy of the GNU General Public License     *
  *   along with this program; if not, write to the                         *
  *   Free Software Foundation, Inc.,                                       *
- *   59 Temple Place - Suite 330, Boston, MA  02111-1307, USA.             *
+ *   51 Franklin Street, Fifth Floor, Boston, MA  02110-1301, USA.         *
  ***************************************************************************/
 
+#include <algorithm>
+
+#include <QCoreApplication>
+
 #include "core.h"
-#include "server.h"
-#include "global.h"
-#include "util.h"
-#include "coreproxy.h"
+#include "coreauthhandler.h"
+#include "coresession.h"
+#include "coresettings.h"
+#include "logger.h"
+#include "internalpeer.h"
+#include "network.h"
+#include "postgresqlstorage.h"
+#include "quassel.h"
+#include "sqlauthenticator.h"
 #include "sqlitestorage.h"
+#include "util.h"
+
+// Currently building with LDAP bindings is optional.
+#ifdef HAVE_LDAP
+#include "ldapauthenticator.h"
+#endif
+
+// migration related
+#include <QFile>
+#ifdef Q_OS_WIN
+#  include <windows.h>
+#else
+#  include <unistd.h>
+#  include <termios.h>
+#endif /* Q_OS_WIN */
+
+// ==============================
+//  Custom Events
+// ==============================
+const int Core::AddClientEventId = QEvent::registerEventType();
+
+class AddClientEvent : public QEvent
+{
+public:
+    AddClientEvent(RemotePeer *p, UserId uid) : QEvent(QEvent::Type(Core::AddClientEventId)), peer(p), userId(uid) {}
+    RemotePeer *peer;
+    UserId userId;
+};
+
+
+// ==============================
+//  Core
+// ==============================
+Core *Core::_instance{nullptr};
+
+Core *Core::instance()
+{
+    return _instance;
+}
+
+
+Core::Core()
+{
+    if (_instance) {
+        qWarning() << "Recreating core instance!";
+        delete _instance;
+    }
+    _instance = this;
+
+    // Parent all QObject-derived attributes, so when the Core instance gets moved into another
+    // thread, they get moved with it
+    _server.setParent(this);
+    _v6server.setParent(this);
+    _storageSyncTimer.setParent(this);
+}
+
+
+Core::~Core()
+{
+    saveState();
+    qDeleteAll(_connectingClients);
+    qDeleteAll(_sessions);
+    syncStorage();
+    _instance = nullptr;
+}
+
+
+bool Core::init()
+{
+    _startTime = QDateTime::currentDateTime().toUTC(); // for uptime :)
+
+    Quassel::loadTranslation(QLocale::system());
+
+    // check settings version
+    // so far, we only have 1
+    CoreSettings s;
+    if (s.version() != 1) {
+        qCritical() << "Invalid core settings version, terminating!";
+        QCoreApplication::exit(EXIT_FAILURE);
+        return false;
+    }
+
+    // Set up storage and authentication backends
+    registerStorageBackends();
+    registerAuthenticators();
+
+    QProcessEnvironment environment = QProcessEnvironment::systemEnvironment();
+    bool config_from_environment = Quassel::isOptionSet("config-from-environment");
+
+    QString db_backend;
+    QVariantMap db_connectionProperties;
+
+    QString auth_authenticator;
+    QVariantMap auth_properties;
+
+    bool writeError = false;
+
+    if (config_from_environment) {
+        db_backend = environment.value("DB_BACKEND");
+        auth_authenticator = environment.value("AUTH_AUTHENTICATOR");
+    } else {
+        CoreSettings cs;
+
+        QVariantMap dbsettings = cs.storageSettings().toMap();
+        db_backend = dbsettings.value("Backend").toString();
+        db_connectionProperties = dbsettings.value("ConnectionProperties").toMap();
+
+        QVariantMap authSettings = cs.authSettings().toMap();
+        auth_authenticator = authSettings.value("Authenticator", "Database").toString();
+        auth_properties = authSettings.value("AuthProperties").toMap();
+
+        writeError = !cs.isWritable();
+    }
+
+    // legacy
+    _configured = initStorage(db_backend, db_connectionProperties, environment, config_from_environment);
+
+    // Not entirely sure what is 'legacy' about the above, but it seems to be the way things work!
+    if (_configured) {
+        initAuthenticator(auth_authenticator, auth_properties, environment, config_from_environment);
+    }
+
+    if (Quassel::isOptionSet("select-backend") || Quassel::isOptionSet("select-authenticator")) {
+        bool success{true};
+        if (Quassel::isOptionSet("select-backend")) {
+            success &= selectBackend(Quassel::optionValue("select-backend"));
+        }
+        if (Quassel::isOptionSet("select-authenticator")) {
+            success &= selectAuthenticator(Quassel::optionValue("select-authenticator"));
+        }
+        QCoreApplication::exit(success ? EXIT_SUCCESS : EXIT_FAILURE);
+        return success;
+    }
+
+    if (!_configured) {
+        if (config_from_environment) {
+            _configured = initStorage(db_backend, db_connectionProperties, environment, config_from_environment, true);
+            initAuthenticator(auth_authenticator, auth_properties, environment, config_from_environment, true);
+
+            if (!_configured) {
+                qWarning() << "Cannot configure from environment";
+                QCoreApplication::exit(EXIT_FAILURE);
+                return false;
+            }
+        }
+        else {
+            if (_registeredStorageBackends.empty()) {
+                quWarning() << qPrintable(tr("Could not initialize any storage backend! Exiting..."));
+                quWarning()
+                        << qPrintable(tr("Currently, Quassel supports SQLite3 and PostgreSQL. You need to build your\n"
+                                         "Qt library with the sqlite or postgres plugin enabled in order for quasselcore\n"
+                                         "to work."));
+                QCoreApplication::exit(EXIT_FAILURE); // TODO make this less brutal (especially for mono client -> popup)
+                return false;
+            }
+
+            if (writeError) {
+                qWarning() << "Cannot write quasselcore configuration; probably a permission problem.";
+                QCoreApplication::exit(EXIT_FAILURE);
+                return false;
+            }
+
+            quInfo() << "Core is currently not configured! Please connect with a Quassel Client for basic setup.";
+        }
+    }
+    else {
+        if (Quassel::isOptionSet("add-user")) {
+            bool success = createUser();
+            QCoreApplication::exit(success ? EXIT_SUCCESS : EXIT_FAILURE);
+            return success;
+        }
+
+        if (Quassel::isOptionSet("change-userpass")) {
+            bool success = changeUserPass(Quassel::optionValue("change-userpass"));
+            QCoreApplication::exit(success ? EXIT_SUCCESS : EXIT_FAILURE);
+            return success;
+        }
+
+        _strictIdentEnabled = Quassel::isOptionSet("strict-ident");
+        if (_strictIdentEnabled) {
+            cacheSysIdent();
+        }
+
+        if (Quassel::isOptionSet("oidentd")) {
+            _oidentdConfigGenerator = new OidentdConfigGenerator(this);
+        }
+
+        Quassel::registerReloadHandler([]() {
+            // Currently, only reloading SSL certificates and the sysident cache is supported
+            if (Core::instance()) {
+                Core::instance()->cacheSysIdent();
+                Core::instance()->reloadCerts();
+                return true;
+            }
+            return false;
+        });
+
+        connect(&_storageSyncTimer, SIGNAL(timeout()), this, SLOT(syncStorage()));
+        _storageSyncTimer.start(10 * 60 * 1000); // 10 minutes
+    }
+
+    connect(&_server, SIGNAL(newConnection()), this, SLOT(incomingConnection()));
+    connect(&_v6server, SIGNAL(newConnection()), this, SLOT(incomingConnection()));
+
+    if (!startListening()) {
+        QCoreApplication::exit(EXIT_FAILURE);  // TODO make this less brutal
+        return false;
+    }
+
+    if (_configured && !Quassel::isOptionSet("norestore")) {
+        Core::restoreState();
+    }
+
+    return true;
+}
+
+/*** Session Restore ***/
+
+void Core::saveState()
+{
+    if (_storage) {
+        QVariantList activeSessions;
+        for (auto &&user : instance()->_sessions.keys())
+            activeSessions << QVariant::fromValue<UserId>(user);
+        _storage->setCoreState(activeSessions);
+    }
+}
+
+
+void Core::restoreState()
+{
+    if (!_configured) {
+        quWarning() << qPrintable(tr("Cannot restore a state for an unconfigured core!"));
+        return;
+    }
+    if (_sessions.count()) {
+        quWarning() << qPrintable(tr("Calling restoreState() even though active sessions exist!"));
+        return;
+    }
 
-#include <QtSql>
-#include <QSettings>
+    CoreSettings s;
+    /* We don't check, since we are at the first version since switching to Git
+    uint statever = s.coreState().toMap()["CoreStateVersion"].toUInt();
+    if(statever < 1) {
+      quWarning() << qPrintable(tr("Core state too old, ignoring..."));
+      return;
+    }
+    */
 
-Core *Core::instanceptr = 0;
+    const QList<QVariant> &activeSessionsFallback = s.coreState().toMap()["ActiveSessions"].toList();
+    QVariantList activeSessions = instance()->_storage->getCoreState(activeSessionsFallback);
 
-Core * Core::instance() {
-  if(instanceptr) return instanceptr;
-  instanceptr = new Core();
-  instanceptr->init();
-  return instanceptr;
+    if (activeSessions.count() > 0) {
+        quInfo() << "Restoring previous core state...";
+        for(auto &&v : activeSessions) {
+            UserId user = v.value<UserId>();
+            sessionForUser(user, true);
+        }
+    }
 }
 
-void Core::destroy() {
-  delete instanceptr;
-  instanceptr = 0;
+
+/*** Core Setup ***/
+
+QString Core::setup(const QString &adminUser, const QString &adminPassword, const QString &backend, const QVariantMap &setupData, const QString &authenticator, const QVariantMap &authSetupData)
+{
+    return instance()->setupCore(adminUser, adminPassword, backend, setupData, authenticator, authSetupData);
 }
 
-Core::Core() {
-  qDebug() << "core";
+
+QString Core::setupCore(const QString &adminUser, const QString &adminPassword, const QString &backend, const QVariantMap &setupData, const QString &authenticator, const QVariantMap &authSetupData)
+{
+    if (_configured)
+        return tr("Core is already configured! Not configuring again...");
+
+    if (adminUser.isEmpty() || adminPassword.isEmpty()) {
+        return tr("Admin user or password not set.");
+    }
+    if (!(_configured = initStorage(backend, setupData, {}, false, true))) {
+        return tr("Could not setup storage!");
+    }
+
+    quInfo() << "Selected authenticator:" << authenticator;
+    if (!(_configured = initAuthenticator(authenticator, authSetupData, {}, false, true)))
+    {
+        return tr("Could not setup authenticator!");
+    }
+
+    if (!saveBackendSettings(backend, setupData)) {
+        return tr("Could not save backend settings, probably a permission problem.");
+    }
+    saveAuthenticatorSettings(authenticator, authSetupData);
+
+    quInfo() << qPrintable(tr("Creating admin user..."));
+    _storage->addUser(adminUser, adminPassword);
+    cacheSysIdent();
+    startListening(); // TODO check when we need this
+    return QString();
 }
 
-void Core::init() {
-  if(!SqliteStorage::isAvailable()) {
-    qFatal("Sqlite is currently required! Please make sure your Qt library has sqlite support enabled.");
-  }
-  //SqliteStorage::init();
-  storage = new SqliteStorage();
-  connect(Global::instance(), SIGNAL(dataPutLocally(UserId, QString)), this, SLOT(updateGlobalData(UserId, QString)));
-  connect(&server, SIGNAL(newConnection()), this, SLOT(incomingConnection()));
-  //startListening(); // FIXME
-  if(Global::runMode == Global::Monolithic) {  // TODO Make GUI user configurable
-    try {
-      guiUser = storage->validateUser("Default", "password");
-    } catch(Storage::AuthError) {
-      guiUser = storage->addUser("Default", "password");
+
+QString Core::setupCoreForInternalUsage()
+{
+    Q_ASSERT(!_registeredStorageBackends.empty());
+
+    qsrand(QDateTime::currentDateTime().toMSecsSinceEpoch());
+    int pass = 0;
+    for (int i = 0; i < 10; i++) {
+        pass *= 10;
+        pass += qrand() % 10;
     }
-    Q_ASSERT(guiUser);
-    Global::setGuiUser(guiUser);
-    createSession(guiUser);
-  } else guiUser = 0;
 
-  // Read global settings from config file
-  QSettings s;
-  s.beginGroup("Global");
-  foreach(QString unum, s.childGroups()) {
-    UserId uid = unum.toUInt();
-    s.beginGroup(unum);
-    foreach(QString key, s.childKeys()) {
-      Global::updateData(uid, key, s.value(key));
+    // mono client currently needs sqlite
+    return setupCore("AdminUser", QString::number(pass), "SQLite", QVariantMap(), "Database", QVariantMap());
+}
+
+
+/*** Storage Handling ***/
+
+template<typename Storage>
+void Core::registerStorageBackend()
+{
+    auto backend = makeDeferredShared<Storage>(this);
+    if (backend->isAvailable())
+        _registeredStorageBackends.emplace_back(std::move(backend));
+    else
+        backend->deleteLater();
+}
+
+
+void Core::registerStorageBackends()
+{
+    if (_registeredStorageBackends.empty()) {
+        registerStorageBackend<SqliteStorage>();
+        registerStorageBackend<PostgreSqlStorage>();
     }
-    s.endGroup();
-  }
-  s.endGroup();
 }
 
-Core::~Core() {
-  foreach(QTcpSocket *sock, validClients.keys()) {
-    delete sock;
-  }
-  qDeleteAll(sessions);
-  delete storage;
+
+DeferredSharedPtr<Storage> Core::storageBackend(const QString &backendId) const
+{
+    auto it = std::find_if(_registeredStorageBackends.begin(), _registeredStorageBackends.end(),
+                           [backendId](const DeferredSharedPtr<Storage> &backend) {
+                               return backend->displayName() == backendId;
+                           });
+    return it != _registeredStorageBackends.end() ? *it : nullptr;
 }
 
-CoreSession *Core::session(UserId uid) {
-  Core *core = instance();
-  if(core->sessions.contains(uid)) return core->sessions[uid];
-  else return 0;
+// old db settings:
+// "Type" => "sqlite"
+bool Core::initStorage(const QString &backend, const QVariantMap &settings,
+                       const QProcessEnvironment &environment, bool loadFromEnvironment, bool setup)
+{
+    if (backend.isEmpty()) {
+        quWarning() << "No storage backend selected!";
+        return false;
+    }
+
+    auto storage = storageBackend(backend);
+    if (!storage) {
+        qCritical() << "Selected storage backend is not available:" << backend;
+        return false;
+    }
+
+    Storage::State storageState = storage->init(settings, environment, loadFromEnvironment);
+    switch (storageState) {
+    case Storage::NeedsSetup:
+        if (!setup)
+            return false;  // trigger setup process
+        if (storage->setup(settings, environment, loadFromEnvironment))
+            return initStorage(backend, settings, environment, loadFromEnvironment, false);
+        return false;
+
+    // if initialization wasn't successful, we quit to keep from coming up unconfigured
+    case Storage::NotAvailable:
+        qCritical() << "FATAL: Selected storage backend is not available:" << backend;
+        if (!setup) {
+            QCoreApplication::exit(EXIT_FAILURE);
+        }
+        return false;
+
+    case Storage::IsReady:
+        // delete all other backends
+        _registeredStorageBackends.clear();
+        connect(storage.get(), SIGNAL(bufferInfoUpdated(UserId, const BufferInfo &)),
+                this, SIGNAL(bufferInfoUpdated(UserId, const BufferInfo &)));
+        break;
+    }
+    _storage = std::move(storage);
+    return true;
 }
 
-CoreSession *Core::localSession() {
-  Core *core = instance();
-  if(core->guiUser && core->sessions.contains(core->guiUser)) return core->sessions[core->guiUser];
-  else return 0;
+
+void Core::syncStorage()
+{
+    if (_storage)
+        _storage->sync();
 }
 
-CoreSession *Core::createSession(UserId uid) {
-  Core *core = instance();
-  Q_ASSERT(!core->sessions.contains(uid));
-  CoreSession *sess = new CoreSession(uid, core->storage);
-  core->sessions[uid] = sess;
-  connect(sess, SIGNAL(proxySignal(CoreSignal, QVariant, QVariant, QVariant)), core, SLOT(recvProxySignal(CoreSignal, QVariant, QVariant, QVariant)));
-  return sess;
+
+/*** Storage Access ***/
+bool Core::createNetwork(UserId user, NetworkInfo &info)
+{
+    NetworkId networkId = instance()->_storage->createNetwork(user, info);
+    if (!networkId.isValid())
+        return false;
+
+    info.networkId = networkId;
+    return true;
+}
+
+
+/*** Authenticators ***/
+
+// Authentication handling, now independent from storage.
+template<typename Authenticator>
+void Core::registerAuthenticator()
+{
+    auto authenticator = makeDeferredShared<Authenticator>(this);
+    if (authenticator->isAvailable())
+        _registeredAuthenticators.emplace_back(std::move(authenticator));
+    else
+        authenticator->deleteLater();
+}
+
+
+void Core::registerAuthenticators()
+{
+    if (_registeredAuthenticators.empty()) {
+        registerAuthenticator<SqlAuthenticator>();
+#ifdef HAVE_LDAP
+        registerAuthenticator<LdapAuthenticator>();
+#endif
+    }
 }
 
 
-bool Core::startListening(uint port) {
-  if(!server.listen(QHostAddress::Any, port)) {
-    qWarning(QString(QString("Could not open GUI client port %1: %2").arg(port).arg(server.errorString())).toAscii());
+DeferredSharedPtr<Authenticator> Core::authenticator(const QString &backendId) const
+{
+    auto it = std::find_if(_registeredAuthenticators.begin(), _registeredAuthenticators.end(),
+                           [backendId](const DeferredSharedPtr<Authenticator> &authenticator) {
+                               return authenticator->backendId() == backendId;
+                           });
+    return it != _registeredAuthenticators.end() ? *it : nullptr;
+}
+
+
+// FIXME: Apparently, this is the legacy way of initting storage backends?
+// If there's a not-legacy way, it should be used here
+bool Core::initAuthenticator(const QString &backend, const QVariantMap &settings,
+                             const QProcessEnvironment &environment, bool loadFromEnvironment,
+                             bool setup)
+{
+    if (backend.isEmpty()) {
+        quWarning() << "No authenticator selected!";
+        return false;
+    }
+
+    auto auth = authenticator(backend);
+    if (!auth) {
+        qCritical() << "Selected auth backend is not available:" << backend;
+        return false;
+    }
+
+    Authenticator::State authState = auth->init(settings, environment, loadFromEnvironment);
+    switch (authState) {
+    case Authenticator::NeedsSetup:
+        if (!setup)
+            return false;  // trigger setup process
+        if (auth->setup(settings, environment, loadFromEnvironment))
+            return initAuthenticator(backend, settings, environment, loadFromEnvironment, false);
+        return false;
+
+    // if initialization wasn't successful, we quit to keep from coming up unconfigured
+    case Authenticator::NotAvailable:
+        qCritical() << "FATAL: Selected auth backend is not available:" << backend;
+        if (!setup) {
+            QCoreApplication::exit(EXIT_FAILURE);
+        }
+        return false;
+
+    case Authenticator::IsReady:
+        // delete all other backends
+        _registeredAuthenticators.clear();
+        break;
+    }
+    _authenticator = std::move(auth);
+    return true;
+}
+
+
+/*** Network Management ***/
+
+bool Core::sslSupported()
+{
+#ifdef HAVE_SSL
+    SslServer *sslServer = qobject_cast<SslServer *>(&instance()->_server);
+    return sslServer && sslServer->isCertValid();
+#else
     return false;
-  }
-  qDebug() << "Listening for GUI clients on port" << server.serverPort();
-  return true;
-}
-
-void Core::stopListening() {
-  server.close();
-  qDebug() << "No longer listening for GUI clients.";
-}
-
-void Core::incomingConnection() {
-  // TODO implement SSL
-  QTcpSocket *socket = server.nextPendingConnection();
-  connect(socket, SIGNAL(disconnected()), this, SLOT(clientDisconnected()));
-  connect(socket, SIGNAL(readyRead()), this, SLOT(clientHasData()));
-  blockSizes.insert(socket, (quint32)0);
-  qDebug() << "Client connected from " << socket->peerAddress().toString();
-}
-
-void Core::clientHasData() {
-  QTcpSocket *socket = dynamic_cast<QTcpSocket*>(sender());
-  Q_ASSERT(socket && blockSizes.contains(socket));
-  quint32 bsize = blockSizes.value(socket);
-  QVariant item;
-  while(readDataFromDevice(socket, bsize, item)) {
-    if(validClients.contains(socket)) {
-      QList<QVariant> sigdata = item.toList();
-      if((ClientSignal)sigdata[0].toInt() == GS_UPDATE_GLOBAL_DATA) {
-        processClientUpdate(socket, sigdata[1].toString(), sigdata[2]);
-      } else {
-        sessions[validClients[socket]]->processSignal((ClientSignal)sigdata[0].toInt(), sigdata[1], sigdata[2], sigdata[3]);
-      }
-    } else {
-      // we need to auth the client
-      try {
-        processClientInit(socket, item);
-      } catch(Storage::AuthError) {
-        qWarning() << "Authentification error!";  // FIXME
-        socket->close();
+#endif
+}
+
+
+bool Core::reloadCerts()
+{
+#ifdef HAVE_SSL
+    SslServer *sslServerv4 = qobject_cast<SslServer *>(&_server);
+    bool retv4 = sslServerv4->reloadCerts();
+
+    SslServer *sslServerv6 = qobject_cast<SslServer *>(&_v6server);
+    bool retv6 = sslServerv6->reloadCerts();
+
+    return retv4 && retv6;
+#else
+    // SSL not supported, don't mark configuration reload as failed
+    return true;
+#endif
+}
+
+
+void Core::cacheSysIdent()
+{
+    if (isConfigured()) {
+        _authUserNames = _storage->getAllAuthUserNames();
+    }
+}
+
+
+QString Core::strictSysIdent(UserId user) const
+{
+    if (_authUserNames.contains(user)) {
+        return _authUserNames[user];
+    }
+
+    // A new user got added since we last pulled our cache from the database.
+    // There's no way to avoid a database hit - we don't even know the authname!
+    instance()->cacheSysIdent();
+
+    if (_authUserNames.contains(user)) {
+        return _authUserNames[user];
+    }
+
+    // ...something very weird is going on if we ended up here (an active CoreSession without a corresponding database entry?)
+    qWarning().nospace() << "Unable to find authusername for UserId " << user << ", this should never happen!";
+    return "unknown"; // Should we just terminate the program instead?
+}
+
+
+bool Core::startListening()
+{
+    // in mono mode we only start a local port if a port is specified in the cli call
+    if (Quassel::runMode() == Quassel::Monolithic && !Quassel::isOptionSet("port"))
+        return true;
+
+    bool success = false;
+    uint port = Quassel::optionValue("port").toUInt();
+
+    const QString listen = Quassel::optionValue("listen");
+    const QStringList listen_list = listen.split(",", QString::SkipEmptyParts);
+    if (listen_list.size() > 0) {
+        foreach(const QString listen_term, listen_list) { // TODO: handle multiple interfaces for same TCP version gracefully
+            QHostAddress addr;
+            if (!addr.setAddress(listen_term)) {
+                qCritical() << qPrintable(
+                    tr("Invalid listen address %1")
+                    .arg(listen_term)
+                    );
+            }
+            else {
+                switch (addr.protocol()) {
+                case QAbstractSocket::IPv6Protocol:
+                    if (_v6server.listen(addr, port)) {
+                        quInfo() << qPrintable(
+                            tr("Listening for GUI clients on IPv6 %1 port %2 using protocol version %3")
+                            .arg(addr.toString())
+                            .arg(_v6server.serverPort())
+                            .arg(Quassel::buildInfo().protocolVersion)
+                            );
+                        success = true;
+                    }
+                    else
+                        quWarning() << qPrintable(
+                            tr("Could not open IPv6 interface %1:%2: %3")
+                            .arg(addr.toString())
+                            .arg(port)
+                            .arg(_v6server.errorString()));
+                    break;
+                case QAbstractSocket::IPv4Protocol:
+                    if (_server.listen(addr, port)) {
+                        quInfo() << qPrintable(
+                            tr("Listening for GUI clients on IPv4 %1 port %2 using protocol version %3")
+                            .arg(addr.toString())
+                            .arg(_server.serverPort())
+                            .arg(Quassel::buildInfo().protocolVersion)
+                            );
+                        success = true;
+                    }
+                    else {
+                        // if v6 succeeded on Any, the port will be already in use - don't display the error then
+                        if (!success || _server.serverError() != QAbstractSocket::AddressInUseError)
+                            quWarning() << qPrintable(
+                                tr("Could not open IPv4 interface %1:%2: %3")
+                                .arg(addr.toString())
+                                .arg(port)
+                                .arg(_server.errorString()));
+                    }
+                    break;
+                default:
+                    qCritical() << qPrintable(
+                        tr("Invalid listen address %1, unknown network protocol")
+                        .arg(listen_term)
+                        );
+                    break;
+                }
+            }
+        }
+    }
+    if (!success)
+        quError() << qPrintable(tr("Could not open any network interfaces to listen on!"));
+
+    return success;
+}
+
+
+void Core::stopListening(const QString &reason)
+{
+    bool wasListening = false;
+    if (_server.isListening()) {
+        wasListening = true;
+        _server.close();
+    }
+    if (_v6server.isListening()) {
+        wasListening = true;
+        _v6server.close();
+    }
+    if (wasListening) {
+        if (reason.isEmpty())
+            quInfo() << "No longer listening for GUI clients.";
+        else
+            quInfo() << qPrintable(reason);
+    }
+}
+
+
+void Core::incomingConnection()
+{
+    QTcpServer *server = qobject_cast<QTcpServer *>(sender());
+    Q_ASSERT(server);
+    while (server->hasPendingConnections()) {
+        QTcpSocket *socket = server->nextPendingConnection();
+
+        CoreAuthHandler *handler = new CoreAuthHandler(socket, this);
+        _connectingClients.insert(handler);
+
+        connect(handler, SIGNAL(disconnected()), SLOT(clientDisconnected()));
+        connect(handler, SIGNAL(socketError(QAbstractSocket::SocketError,QString)), SLOT(socketError(QAbstractSocket::SocketError,QString)));
+        connect(handler, SIGNAL(handshakeComplete(RemotePeer*,UserId)), SLOT(setupClientSession(RemotePeer*,UserId)));
+
+        quInfo() << qPrintable(tr("Client connected from"))  << qPrintable(socket->peerAddress().toString());
+
+        if (!_configured) {
+            stopListening(tr("Closing server for basic setup."));
+        }
+    }
+}
+
+
+// Potentially called during the initialization phase (before handing the connection off to the session)
+void Core::clientDisconnected()
+{
+    CoreAuthHandler *handler = qobject_cast<CoreAuthHandler *>(sender());
+    Q_ASSERT(handler);
+
+    quInfo() << qPrintable(tr("Non-authed client disconnected:")) << qPrintable(handler->socket()->peerAddress().toString());
+    _connectingClients.remove(handler);
+    handler->deleteLater();
+
+    // make server listen again if still not configured
+    if (!_configured) {
+        startListening();
+    }
+
+    // TODO remove unneeded sessions - if necessary/possible...
+    // Suggestion: kill sessions if they are not connected to any network and client.
+}
+
+
+void Core::setupClientSession(RemotePeer *peer, UserId uid)
+{
+    CoreAuthHandler *handler = qobject_cast<CoreAuthHandler *>(sender());
+    Q_ASSERT(handler);
+
+    // From now on everything is handled by the client session
+    disconnect(handler, 0, this, 0);
+    _connectingClients.remove(handler);
+    handler->deleteLater();
+
+    // Find or create session for validated user
+    sessionForUser(uid);
+
+    // as we are currently handling an event triggered by incoming data on this socket
+    // it is unsafe to directly move the socket to the client thread.
+    QCoreApplication::postEvent(this, new AddClientEvent(peer, uid));
+}
+
+
+void Core::customEvent(QEvent *event)
+{
+    if (event->type() == AddClientEventId) {
+        AddClientEvent *addClientEvent = static_cast<AddClientEvent *>(event);
+        addClientHelper(addClientEvent->peer, addClientEvent->userId);
         return;
-      } catch(Exception e) {
-        qWarning() << "Client init error:" << e.msg();
-        socket->close();
+    }
+}
+
+
+void Core::addClientHelper(RemotePeer *peer, UserId uid)
+{
+    // Find or create session for validated user
+    SessionThread *session = sessionForUser(uid);
+    session->addClient(peer);
+}
+
+
+void Core::setupInternalClientSession(InternalPeer *clientPeer)
+{
+    if (!_configured) {
+        stopListening();
+        setupCoreForInternalUsage();
+    }
+
+    UserId uid;
+    if (_storage) {
+        uid = _storage->internalUser();
+    }
+    else {
+        quWarning() << "Core::setupInternalClientSession(): You're trying to run monolithic Quassel with an unusable Backend! Go fix it!";
         return;
-      }
-    }
-    blockSizes[socket] = bsize = 0;
-  }
-  blockSizes[socket] = bsize;
-}
-
-void Core::clientDisconnected() {
-  QTcpSocket *socket = dynamic_cast<QTcpSocket*>(sender());
-  blockSizes.remove(socket);
-  validClients.remove(socket);
-  qDebug() << "Client disconnected.";
-  // TODO remove unneeded sessions - if necessary/possible...
-}
-
-void Core::processClientInit(QTcpSocket *socket, const QVariant &v) {
-  VarMap msg = v.toMap();
-  if(msg["GUIProtocol"].toUInt() != GUI_PROTOCOL) {
-    //qWarning() << "Client version mismatch.";
-    throw Exception("GUI client version mismatch");
-  }
-  // Auth
-  UserId uid = storage->validateUser(msg["User"].toString(), msg["Password"].toString());  // throws exception if this failed
-
-  // Find or create session for validated user
-  CoreSession *sess;
-  if(sessions.contains(uid)) sess = sessions[uid];
-  else {
-    sess = createSession(uid);
-    validClients[socket] = uid;
-  }
-  VarMap reply;
-  VarMap coreData;
-  // FIXME
-  QStringList dataKeys = Global::keys(uid);
-  QString key;
-  foreach(key, dataKeys) {
-    coreData[key] = Global::data(key);
-  }
-  reply["CoreData"] = coreData;
-  reply["SessionState"] = sess->sessionState();
-  QList<QVariant> sigdata;
-  sigdata.append(CS_CORE_STATE); sigdata.append(QVariant(reply)); sigdata.append(QVariant()); sigdata.append(QVariant());
-  writeDataToDevice(socket, QVariant(sigdata));
-  sess->sendServerStates();
-}
-
-void Core::processClientUpdate(QTcpSocket *socket, QString key, const QVariant &data) {
-  UserId uid = validClients[socket];
-  Global::updateData(uid, key, data);
-  QList<QVariant> sigdata;
-  sigdata.append(CS_UPDATE_GLOBAL_DATA); sigdata.append(key); sigdata.append(data); sigdata.append(QVariant());
-  foreach(QTcpSocket *s, validClients.keys()) {
-    if(validClients[s] == uid && s != socket) writeDataToDevice(s, QVariant(sigdata));
-  }
-}
-
-void Core::updateGlobalData(UserId uid, QString key) {
-  QVariant data = Global::data(uid, key);
-  QList<QVariant> sigdata;
-  sigdata.append(CS_UPDATE_GLOBAL_DATA); sigdata.append(key); sigdata.append(data); sigdata.append(QVariant());
-  foreach(QTcpSocket *socket, validClients.keys()) {
-    if(validClients[socket] == uid) writeDataToDevice(socket, QVariant(sigdata));
-  }
-}
-
-void Core::recvProxySignal(CoreSignal sig, QVariant arg1, QVariant arg2, QVariant arg3) {
-  CoreSession *sess = qobject_cast<CoreSession*>(sender());
-  Q_ASSERT(sess);
-  UserId uid = sess->userId();
-  QList<QVariant> sigdata;
-  sigdata.append(sig); sigdata.append(arg1); sigdata.append(arg2); sigdata.append(arg3);
-  //qDebug() << "Sending signal: " << sigdata;
-  foreach(QTcpSocket *socket, validClients.keys()) {
-    if(validClients[socket] == uid) writeDataToDevice(socket, QVariant(sigdata));
-  }
-}
-
-/*
-  // Read global settings from config file
-  QSettings s;
-  s.beginGroup("Global");
-  QString key;
-  foreach(key, s.childKeys()) {
-    global->updateData(key, s.value(key));
-  }
-
-  global->updateData("CoreReady", true);
-  // Now that we are in sync, we can connect signals to automatically store further updates.
-  // I don't think we care if global data changed locally or if it was updated by a client. 
-  connect(global, SIGNAL(dataUpdatedRemotely(QString)), SLOT(globalDataUpdated(QString)));
-  connect(global, SIGNAL(dataPutLocally(QString)), SLOT(globalDataUpdated(QString)));
-
-}
-  */
-
-CoreSession::CoreSession(UserId uid, Storage *_storage) : user(uid), storage(_storage) {
-  coreProxy = new CoreProxy();
-
-  connect(coreProxy, SIGNAL(send(CoreSignal, QVariant, QVariant, QVariant)), this, SIGNAL(proxySignal(CoreSignal, QVariant, QVariant, QVariant)));
-  connect(coreProxy, SIGNAL(requestServerStates()), this, SIGNAL(serverStateRequested()));
-  connect(coreProxy, SIGNAL(gsRequestConnect(QStringList)), this, SLOT(connectToIrc(QStringList)));
-  connect(coreProxy, SIGNAL(gsUserInput(BufferId, QString)), this, SLOT(msgFromGui(BufferId, QString)));
-  connect(coreProxy, SIGNAL(gsImportBacklog()), storage, SLOT(importOldBacklog()));
-  connect(coreProxy, SIGNAL(gsRequestBacklog(BufferId, QVariant, QVariant)), this, SLOT(sendBacklog(BufferId, QVariant, QVariant)));
-  connect(this, SIGNAL(displayMsg(Message)), coreProxy, SLOT(csDisplayMsg(Message)));
-  connect(this, SIGNAL(displayStatusMsg(QString, QString)), coreProxy, SLOT(csDisplayStatusMsg(QString, QString)));
-  connect(this, SIGNAL(backlogData(BufferId, QList<QVariant>, bool)), coreProxy, SLOT(csBacklogData(BufferId, QList<QVariant>, bool)));
-  connect(this, SIGNAL(bufferIdUpdated(BufferId)), coreProxy, SLOT(csUpdateBufferId(BufferId)));
-  connect(storage, SIGNAL(bufferIdUpdated(BufferId)), coreProxy, SLOT(csUpdateBufferId(BufferId)));
-  connect(Global::instance(), SIGNAL(dataUpdatedRemotely(UserId, QString)), this, SLOT(globalDataUpdated(UserId, QString)));
-  connect(Global::instance(), SIGNAL(dataPutLocally(UserId, QString)), this, SLOT(globalDataUpdated(UserId, QString)));
-}
-
-CoreSession::~CoreSession() {
-
-}
-
-UserId CoreSession::userId() {
-  return user;
-}
-
-void CoreSession::processSignal(ClientSignal sig, QVariant arg1, QVariant arg2, QVariant arg3) {
-  coreProxy->recv(sig, arg1, arg2, arg3);
-}
-
-void CoreSession::globalDataUpdated(UserId uid, QString key) {
-  Q_ASSERT(uid == userId());
-  QVariant data = Global::data(userId(), key);
-  QSettings s;
-  s.setValue(QString("Global/%1/").arg(userId())+key, data);
-}
-
-void CoreSession::connectToIrc(QStringList networks) {
-  foreach(QString net, networks) {
-    if(servers.contains(net)) {
+    }
+
+    InternalPeer *corePeer = new InternalPeer(this);
+    corePeer->setPeer(clientPeer);
+    clientPeer->setPeer(corePeer);
+
+    // Find or create session for validated user
+    SessionThread *sessionThread = sessionForUser(uid);
+    sessionThread->addClient(corePeer);
+}
+
+
+SessionThread *Core::sessionForUser(UserId uid, bool restore)
+{
+    if (_sessions.contains(uid))
+        return _sessions[uid];
+
+    SessionThread *session = new SessionThread(uid, restore, strictIdentEnabled(), this);
+    _sessions[uid] = session;
+    session->start();
+    return session;
+}
+
+
+void Core::socketError(QAbstractSocket::SocketError err, const QString &errorString)
+{
+    quWarning() << QString("Socket error %1: %2").arg(err).arg(errorString);
+}
 
-    } else {
-      Server *server = new Server(userId(), net);
-      connect(this, SIGNAL(serverStateRequested()), server, SLOT(sendState()));
-      connect(this, SIGNAL(connectToIrc(QString)), server, SLOT(connectToIrc(QString)));
-      connect(this, SIGNAL(disconnectFromIrc(QString)), server, SLOT(disconnectFromIrc(QString)));
-      connect(this, SIGNAL(msgFromGui(QString, QString, QString)), server, SLOT(userInput(QString, QString, QString)));
 
-      connect(server, SIGNAL(connected(QString)), this, SLOT(serverConnected(QString)));
-      connect(server, SIGNAL(disconnected(QString)), this, SLOT(serverDisconnected(QString)));
+QVariantList Core::backendInfo()
+{
+    instance()->registerStorageBackends();
 
-      connect(server, SIGNAL(serverState(QString, VarMap)), coreProxy, SLOT(csServerState(QString, VarMap)));
-      //connect(server, SIGNAL(displayMsg(Message)), this, SLOT(recvMessageFromServer(Message)));
-      connect(server, SIGNAL(displayMsg(Message::Type, QString, QString, QString, quint8)), this, SLOT(recvMessageFromServer(Message::Type, QString, QString, QString, quint8)));
-      connect(server, SIGNAL(displayStatusMsg(QString)), this, SLOT(recvStatusMsgFromServer(QString)));
-      connect(server, SIGNAL(modeSet(QString, QString, QString)), coreProxy, SLOT(csModeSet(QString, QString, QString)));
-      connect(server, SIGNAL(topicSet(QString, QString, QString)), coreProxy, SLOT(csTopicSet(QString, QString, QString)));
-      connect(server, SIGNAL(nickAdded(QString, QString, VarMap)), coreProxy, SLOT(csNickAdded(QString, QString, VarMap)));
-      connect(server, SIGNAL(nickRenamed(QString, QString, QString)), coreProxy, SLOT(csNickRenamed(QString, QString, QString)));
-      connect(server, SIGNAL(nickRemoved(QString, QString)), coreProxy, SLOT(csNickRemoved(QString, QString)));
-      connect(server, SIGNAL(nickUpdated(QString, QString, VarMap)), coreProxy, SLOT(csNickUpdated(QString, QString, VarMap)));
-      connect(server, SIGNAL(ownNickSet(QString, QString)), coreProxy, SLOT(csOwnNickSet(QString, QString)));
-      connect(server, SIGNAL(queryRequested(QString, QString)), coreProxy, SLOT(csQueryRequested(QString, QString)));
-      // TODO add error handling
-      connect(server, SIGNAL(connected(QString)), coreProxy, SLOT(csServerConnected(QString)));
-      connect(server, SIGNAL(disconnected(QString)), coreProxy, SLOT(csServerDisconnected(QString)));
+    QVariantList backendInfos;
+    for (auto &&backend : instance()->_registeredStorageBackends) {
+        QVariantMap v;
+        v["BackendId"]   = backend->backendId();
+        v["DisplayName"] = backend->displayName();
+        v["Description"] = backend->description();
+        v["SetupData"]   = backend->setupData(); // ignored by legacy clients
 
-      server->start();
-      servers[net] = server;
+        // TODO Protocol Break: Remove legacy (cf. authenticatorInfo())
+        const auto &setupData = backend->setupData();
+        QStringList setupKeys;
+        QVariantMap setupDefaults;
+        for (int i = 0; i + 2 < setupData.size(); i += 3) {
+            setupKeys << setupData[i].toString();
+            setupDefaults[setupData[i].toString()] = setupData[i + 2];
+        }
+        v["SetupKeys"]     = setupKeys;
+        v["SetupDefaults"] = setupDefaults;
+        // TODO Protocol Break: Remove
+        v["IsDefault"]     = (backend->backendId() == "SQLite"); // newer clients will just use the first in the list
+
+        backendInfos << v;
     }
-    emit connectToIrc(net);
-  }
+    return backendInfos;
 }
 
-void CoreSession::serverConnected(QString net) {
-  storage->getBufferId(userId(), net); // create status buffer
+
+QVariantList Core::authenticatorInfo()
+{
+    instance()->registerAuthenticators();
+
+    QVariantList authInfos;
+    for(auto &&backend : instance()->_registeredAuthenticators) {
+        QVariantMap v;
+        v["BackendId"]   = backend->backendId();
+        v["DisplayName"] = backend->displayName();
+        v["Description"] = backend->description();
+        v["SetupData"]   = backend->setupData();
+        authInfos << v;
+    }
+    return authInfos;
 }
 
-void CoreSession::serverDisconnected(QString net) {
-  delete servers[net];
-  servers.remove(net);
-  coreProxy->csServerDisconnected(net);
+// migration / backend selection
+bool Core::selectBackend(const QString &backend)
+{
+    // reregister all storage backends
+    registerStorageBackends();
+    auto storage = storageBackend(backend);
+    if (!storage) {
+        QStringList backends;
+        std::transform(_registeredStorageBackends.begin(), _registeredStorageBackends.end(),
+                       std::back_inserter(backends), [](const DeferredSharedPtr<Storage>& backend) {
+                           return backend->displayName();
+                       });
+        quWarning() << qPrintable(tr("Unsupported storage backend: %1").arg(backend));
+        quWarning() << qPrintable(tr("Supported backends are:")) << qPrintable(backends.join(", "));
+        return false;
+    }
+
+    QVariantMap settings = promptForSettings(storage.get());
+
+    Storage::State storageState = storage->init(settings);
+    switch (storageState) {
+    case Storage::IsReady:
+        if (!saveBackendSettings(backend, settings)) {
+            qCritical() << qPrintable(QString("Could not save backend settings, probably a permission problem."));
+        }
+        quWarning() << qPrintable(tr("Switched storage backend to: %1").arg(backend));
+        quWarning() << qPrintable(tr("Backend already initialized. Skipping Migration..."));
+        return true;
+    case Storage::NotAvailable:
+        qCritical() << qPrintable(tr("Storage backend is not available: %1").arg(backend));
+        return false;
+    case Storage::NeedsSetup:
+        if (!storage->setup(settings)) {
+            quWarning() << qPrintable(tr("Unable to setup storage backend: %1").arg(backend));
+            return false;
+        }
+
+        if (storage->init(settings) != Storage::IsReady) {
+            quWarning() << qPrintable(tr("Unable to initialize storage backend: %1").arg(backend));
+            return false;
+        }
+
+        if (!saveBackendSettings(backend, settings)) {
+            qCritical() << qPrintable(QString("Could not save backend settings, probably a permission problem."));
+        }
+        quWarning() << qPrintable(tr("Switched storage backend to: %1").arg(backend));
+        break;
+    }
+
+    // let's see if we have a current storage object we can migrate from
+    auto reader = getMigrationReader(_storage.get());
+    auto writer = getMigrationWriter(storage.get());
+    if (reader && writer) {
+        qDebug() << qPrintable(tr("Migrating storage backend %1 to %2...").arg(_storage->displayName(), storage->displayName()));
+        _storage.reset();
+        storage.reset();
+        if (reader->migrateTo(writer.get())) {
+            qDebug() << "Migration finished!";
+            qDebug() << qPrintable(tr("Migration finished!"));
+            if (!saveBackendSettings(backend, settings)) {
+                qCritical() << qPrintable(QString("Could not save backend settings, probably a permission problem."));
+                return false;
+            }
+            return true;
+        }
+        quWarning() << qPrintable(tr("Unable to migrate storage backend! (No migration writer for %1)").arg(backend));
+        return false;
+    }
+
+    // inform the user why we cannot merge
+    if (!_storage) {
+        quWarning() << qPrintable(tr("No currently active storage backend. Skipping migration..."));
+    }
+    else if (!reader) {
+        quWarning() << qPrintable(tr("Currently active storage backend does not support migration: %1").arg(_storage->displayName()));
+    }
+    if (writer) {
+        quWarning() << qPrintable(tr("New storage backend does not support migration: %1").arg(backend));
+    }
+
+    // so we were unable to merge, but let's create a user \o/
+    _storage = std::move(storage);
+    createUser();
+    return true;
+}
+
+// TODO: I am not sure if this function is implemented correctly.
+// There is currently no concept of migraiton between auth backends.
+bool Core::selectAuthenticator(const QString &backend)
+{
+    // Register all authentication backends.
+    registerAuthenticators();
+    auto auther = authenticator(backend);
+    if (!auther) {
+        QStringList authenticators;
+        std::transform(_registeredAuthenticators.begin(), _registeredAuthenticators.end(),
+                       std::back_inserter(authenticators), [](const DeferredSharedPtr<Authenticator>& authenticator) {
+                           return authenticator->displayName();
+                       });
+        quWarning() << qPrintable(tr("Unsupported authenticator: %1").arg(backend));
+        quWarning() << qPrintable(tr("Supported authenticators are:")) << qPrintable(authenticators.join(", "));
+        return false;
+    }
+
+    QVariantMap settings = promptForSettings(auther.get());
+
+    Authenticator::State state = auther->init(settings);
+    switch (state) {
+    case Authenticator::IsReady:
+        saveAuthenticatorSettings(backend, settings);
+        quWarning() << qPrintable(tr("Switched authenticator to: %1").arg(backend));
+        return true;
+    case Authenticator::NotAvailable:
+        qCritical() << qPrintable(tr("Authenticator is not available: %1").arg(backend));
+        return false;
+    case Authenticator::NeedsSetup:
+        if (!auther->setup(settings)) {
+            quWarning() << qPrintable(tr("Unable to setup authenticator: %1").arg(backend));
+            return false;
+        }
+
+        if (auther->init(settings) != Authenticator::IsReady) {
+            quWarning() << qPrintable(tr("Unable to initialize authenticator: %1").arg(backend));
+            return false;
+        }
+
+        saveAuthenticatorSettings(backend, settings);
+        quWarning() << qPrintable(tr("Switched authenticator to: %1").arg(backend));
+    }
+
+    _authenticator = std::move(auther);
+    return true;
+}
+
+
+bool Core::createUser()
+{
+    QTextStream out(stdout);
+    QTextStream in(stdin);
+    out << "Add a new user:" << endl;
+    out << "Username: ";
+    out.flush();
+    QString username = in.readLine().trimmed();
+
+    disableStdInEcho();
+    out << "Password: ";
+    out.flush();
+    QString password = in.readLine().trimmed();
+    out << endl;
+    out << "Repeat Password: ";
+    out.flush();
+    QString password2 = in.readLine().trimmed();
+    out << endl;
+    enableStdInEcho();
+
+    if (password != password2) {
+        quWarning() << "Passwords don't match!";
+        return false;
+    }
+    if (password.isEmpty()) {
+        quWarning() << "Password is empty!";
+        return false;
+    }
+
+    if (_configured && _storage->addUser(username, password).isValid()) {
+        out << "Added user " << username << " successfully!" << endl;
+        return true;
+    }
+    else {
+        quWarning() << "Unable to add user:" << qPrintable(username);
+        return false;
+    }
 }
 
-void CoreSession::msgFromGui(BufferId bufid, QString msg) {
-  emit msgFromGui(bufid.network(), bufid.buffer(), msg);
+
+bool Core::changeUserPass(const QString &username)
+{
+    QTextStream out(stdout);
+    QTextStream in(stdin);
+    UserId userId = _storage->getUserId(username);
+    if (!userId.isValid()) {
+        out << "User " << username << " does not exist." << endl;
+        return false;
+    }
+
+    if (!canChangeUserPassword(userId)) {
+        out << "User " << username << " is configured through an auth provider that has forbidden manual password changing." << endl;
+        return false;
+    }
+
+    out << "Change password for user: " << username << endl;
+
+    disableStdInEcho();
+    out << "New Password: ";
+    out.flush();
+    QString password = in.readLine().trimmed();
+    out << endl;
+    out << "Repeat Password: ";
+    out.flush();
+    QString password2 = in.readLine().trimmed();
+    out << endl;
+    enableStdInEcho();
+
+    if (password != password2) {
+        quWarning() << "Passwords don't match!";
+        return false;
+    }
+    if (password.isEmpty()) {
+        quWarning() << "Password is empty!";
+        return false;
+    }
+
+    if (_configured && _storage->updateUser(userId, password)) {
+        out << "Password changed successfully!" << endl;
+        return true;
+    }
+    else {
+        quWarning() << "Failed to change password!";
+        return false;
+    }
 }
 
-// ALL messages coming pass through these functions before going to the GUI.
-// So this is the perfect place for storing the backlog and log stuff.
 
-void CoreSession::recvMessageFromServer(Message::Type type, QString target, QString text, QString sender, quint8 flags) {
-  Server *s = qobject_cast<Server*>(this->sender());
-  Q_ASSERT(s);
-  BufferId buf;
-  if((flags & Message::PrivMsg) && !(flags & Message::Self)) {
-    buf = storage->getBufferId(user, s->getNetwork(), nickFromMask(sender));
-  } else {
-    buf = storage->getBufferId(user, s->getNetwork(), target);
-  }
-  Message msg(buf, type, text, sender, flags);
-  msg.msgId = storage->logMessage(msg); //qDebug() << msg.msgId;
-  Q_ASSERT(msg.msgId);
-  emit displayMsg(msg);
+bool Core::changeUserPassword(UserId userId, const QString &password)
+{
+    if (!isConfigured() || !userId.isValid())
+        return false;
+
+    if (!canChangeUserPassword(userId))
+        return false;
+
+    return instance()->_storage->updateUser(userId, password);
 }
 
-void CoreSession::recvStatusMsgFromServer(QString msg) {
-  Server *s = qobject_cast<Server*>(sender());
-  Q_ASSERT(s);
-  emit displayStatusMsg(s->getNetwork(), msg);
+// TODO: this code isn't currently 100% optimal because the core
+// doesn't know it can have multiple auth providers configured (there aren't
+// multiple auth providers at the moment anyway) and we have hardcoded the
+// Database provider to be always allowed.
+bool Core::canChangeUserPassword(UserId userId)
+{
+    QString authProvider = instance()->_storage->getUserAuthenticator(userId);
+    if (authProvider != "Database") {
+        if (authProvider != instance()->_authenticator->backendId()) {
+            return false;
+        }
+        else if (instance()->_authenticator->canChangePassword()) {
+            return false;
+        }
+    }
+    return true;
 }
 
 
-QList<BufferId> CoreSession::buffers() const {
-  return storage->requestBuffers(user);
+std::unique_ptr<AbstractSqlMigrationReader> Core::getMigrationReader(Storage *storage)
+{
+    if (!storage)
+        return nullptr;
+
+    AbstractSqlStorage *sqlStorage = qobject_cast<AbstractSqlStorage *>(storage);
+    if (!sqlStorage) {
+        qDebug() << "Core::migrateDb(): only SQL based backends can be migrated!";
+        return nullptr;
+    }
+
+    return sqlStorage->createMigrationReader();
 }
 
 
-QVariant CoreSession::sessionState() {
-  VarMap v;
-  QList<QVariant> bufs;
-  foreach(BufferId id, storage->requestBuffers(user)) { bufs.append(QVariant::fromValue(id)); }
-  v["Buffers"] = bufs;
+std::unique_ptr<AbstractSqlMigrationWriter> Core::getMigrationWriter(Storage *storage)
+{
+    if (!storage)
+        return nullptr;
+
+    AbstractSqlStorage *sqlStorage = qobject_cast<AbstractSqlStorage *>(storage);
+    if (!sqlStorage) {
+        qDebug() << "Core::migrateDb(): only SQL based backends can be migrated!";
+        return nullptr;
+    }
+
+    return sqlStorage->createMigrationWriter();
+}
+
 
-  return v;
+bool Core::saveBackendSettings(const QString &backend, const QVariantMap &settings)
+{
+    QVariantMap dbsettings;
+    dbsettings["Backend"] = backend;
+    dbsettings["ConnectionProperties"] = settings;
+    CoreSettings s = CoreSettings();
+    s.setStorageSettings(dbsettings);
+    return s.sync();
 }
 
-void CoreSession::sendServerStates() {
-  emit serverStateRequested();
+
+void Core::saveAuthenticatorSettings(const QString &backend, const QVariantMap &settings)
+{
+    QVariantMap dbsettings;
+    dbsettings["Authenticator"] = backend;
+    dbsettings["AuthProperties"] = settings;
+    CoreSettings().setAuthSettings(dbsettings);
 }
 
-void CoreSession::sendBacklog(BufferId id, QVariant v1, QVariant v2) {
-  QList<QVariant> log;
-  QList<Message> msglist;
-  if(v1.type() == QVariant::DateTime) {
+// Generic version of promptForSettings that doesn't care what *type* of
+// backend it runs over.
+template<typename Backend>
+QVariantMap Core::promptForSettings(const Backend *backend)
+{
+    QVariantMap settings;
+    const QVariantList& setupData = backend->setupData();
+
+    if (setupData.isEmpty())
+        return settings;
+
+    QTextStream out(stdout);
+    QTextStream in(stdin);
+    out << "Default values are in brackets" << endl;
 
+    for (int i = 0; i + 2 < setupData.size(); i += 3) {
+        QString key = setupData[i].toString();
+        out << setupData[i+1].toString() << " [" << setupData[i+2].toString() << "]: " << flush;
 
-  } else {
-    msglist = storage->requestMsgs(id, v1.toInt(), v2.toInt());
-  }
+        bool noEcho = key.toLower().contains("password");
+        if (noEcho) {
+            disableStdInEcho();
+        }
+        QString input = in.readLine().trimmed();
+        if (noEcho) {
+            out << endl;
+            enableStdInEcho();
+        }
 
-  // Send messages out in smaller packages - we don't want to make the signal data too large!
-  for(int i = 0; i < msglist.count(); i++) {
-    log.append(QVariant::fromValue(msglist[i]));
-    if(log.count() >= 5) {
-      emit backlogData(id, log, i >= msglist.count() - 1);
-      log.clear();
+        QVariant value{setupData[i+2]};
+        if (!input.isEmpty()) {
+            switch (value.type()) {
+            case QVariant::Int:
+                value = input.toInt();
+                break;
+            default:
+                value = input;
+            }
+        }
+        settings[key] = value;
     }
-  }
-  if(log.count() > 0) emit backlogData(id, log, true);
+    return settings;
 }
 
 
-//Core *core = 0;
+#ifdef Q_OS_WIN
+void Core::stdInEcho(bool on)
+{
+    HANDLE hStdin = GetStdHandle(STD_INPUT_HANDLE);
+    DWORD mode = 0;
+    GetConsoleMode(hStdin, &mode);
+    if (on)
+        mode |= ENABLE_ECHO_INPUT;
+    else
+        mode &= ~ENABLE_ECHO_INPUT;
+    SetConsoleMode(hStdin, mode);
+}
+
+#else
+void Core::stdInEcho(bool on)
+{
+    termios t;
+    tcgetattr(STDIN_FILENO, &t);
+    if (on)
+        t.c_lflag |= ECHO;
+    else
+        t.c_lflag &= ~ECHO;
+    tcsetattr(STDIN_FILENO, TCSANOW, &t);
+}
+
+#endif /* Q_OS_WIN */