If there are roles refs present in the scope, then wrap the UserIdentity
with one that uses the role references in the UserIdentity#isUserInRole(String)
Badly named class that holds the role and user data constraint info for a
path/http method combination, extracted and combined from security
constraints.