Add JWT resource-server security to an existing Spring Boot 4 Maven project — security config, claim-to-role mapping, method security, and tests. Use when asked to secure an API, add JWT or OAuth2 resource server auth, or add roles and permissions. Not for dependency, secret, or image scanning — use security-hardening.