Returns the roles a subject holds now, in the named realm or the ambient
one.
For a person the console roles come from the console roster rather than
the groups, and a roster that cannot be read grants none; an
unauthenticated or unnamed subject holds no configured role.
Parameters
subject: Subject
{ kind, name, authenticated }
OptionalrealmId: string
optional realm id; the ambient realm when absent or
unknown
Returns Held
{ all, configured, why }: every role held, the configured ones,
and why a console role is not held ('' otherwise)
Returns the roles a subject holds now, in the named realm or the ambient one.
For a person the console roles come from the console roster rather than the groups, and a roster that cannot be read grants none; an unauthenticated or unnamed subject holds no configured role.