Reads the roles out of a presented token's claims: an array, a single string, or a space- or comma-separated string.
What it returns is trusted no more than the token it came from.
the token's claims
the role names found, or an empty list
Reads the roles out of a presented token's claims: an array, a single string, or a space- or comma-separated string.
What it returns is trusted no more than the token it came from.