The role-how and vlan-how represent how a user got his/her current VLAN and role. They are not documented because they are meant to be used for debugging and not common use:
Role-How
Code Description
0 Default Logon Role
1 Default for Authentication Type
2 Derived from Server Rules
3 Derived from User Rules
4 Predefined Guest
5 Inherited from Station
6 Forced Role
7 Aruba VSA
8 RFC 3576 Change of Authorization
9 External Captive Portal
10 Default from AAA Profile
11 Assigned by ESI
Vlan-How
Code Description
1 User Rule
2 VLAN from Role
3 Server Rule
4 Aruba VSA
5 MSFT Attributes
6 VLAN from Derived Role