getCachedPropertiesWithLock

Cached access-locked property list if the role cache is still within ROLE_CACHE_TTL_MILLIS; empty list if expired or never cached. The lock list is only meaningful together with the cached roles, so it is gated on the same TTL.