SonarQube 9.x: Configuring API Token Expiration for Least-Privilege Users
Goal We want to enforce least‑privilege access for API tokens in SonarQube 9.x and guarantee that expired tokens are automatically rejected. Constraints & Uncertainty SonarQube 9.x exposes the sonar.auth.token.validity property (default 30 days), while 8.x LTS lacks this setting and relies on session‑only authentication. The permission model allows a Bro