Change record status: 
Project: 
Introduced in branch: 
10.3.x
Introduced in version: 
10.3.0
Description: 

Previously text formats could specify a list of roles in their configuration array that would be granted upon creation of the format. For example:

// Drupal <=10.2.x
// filter.format.restricted_html.yml
...
format: restricted_html
roles:
  - anonymous
  - authenticated
...

Due to several problems this functionality has been deprecated. The roles property should be removed. Instead the respective permission for the text format should be granted to the role separately either via role configuration or via a hook. For example for an installation profile shipping both the text format and the role configuration:

// Drupal >=10.3.x
// user.role.anonymous.yml
...
id: anonymous
permissions:
  - use text format restricted_html
...

// user.role.authenticated.yml
...
id: authenticated
permissions:
  - use text format restricted_html
...

Or for a module shipping a text format that wants to ensure the permissions are granted:

// Drupal >=10.3.x
// MYMODULE.module
/**
 * Implements hook_ENTITY_TYPE_insert() for text formats.
 */
function MYMODULE_filter_format_insert(FilterFormatInterface $format) {
  $permission = $format->getPermissionName();

  user_role_grant_permissions(RoleInterface::ANONYMOUS_ID, [$permission]);
  user_role_grant_permissions(RoleInterface::AUTHENTICATED_ID, [$permission]);
}

Similarly, tests that use the roles property to grant permission to the text format in their test setup, need to grant those permissions explicitly.

Impacts: 
Module developers
Site templates, recipes and distribution developers