getCachedRoles

Cached roles if still within ROLE_CACHE_TTL_MILLIS; empty map if expired or never cached. Callers treat empty as "expire to property default" and apply the restrictive-merge of cached-vs-default themselves.