SonarQube 9.x: Configuring API Token Expiration for Least-Privilege Users
0 reputation · 17 Jul 2020, 17:38 UTC
Goal
We want to enforce least‑privilege access for API tokens in SonarQube 9.x and guarantee that expired tokens are automatically rejected.
Constraints & Uncertainty
SonarQube 9.x exposes the sonar.auth.token.validity property (default 30 days), while 8.x LTS lacks this setting and relies on session‑only authentication. The permission model allows a Browse role, but it is unclear if token‑based requests honor the same role boundaries. Additionally, password resets or account deactivation invalidate all tokens, yet the timing of this invalidation relative to the token‑validity window is not documented.
Unresolved Questions
- Can we apply a different
sonar.auth.token.validityvalue per user or group, or is it strictly global? - Do tokens issued to a user with only the
Browserole receive the same 401 response once the validity period expires, or are they exempted? - What audit mechanisms exist in SonarQube 9.x to track usage of expired or revoked tokens?