Returns only the configured roles a subject holds, for the XACML PIP's role designator; the built-in roles are facts about a request it cannot know.
{ kind, name, authenticated }
Optional
optional realm id
the configured role names
Returns only the configured roles a subject holds, for the XACML PIP's role designator; the built-in roles are facts about a request it cannot know.