Parent: #248
Native authority: SceneTech/AppScene#123
Reproduction
At WebScene 2ffb0dc, FileSystemHandle.queryPermission({mode:"readwrite"}) and requestPermission({mode:"readwrite"}) return granted whenever any write-like grant bit is present. A write/create-only opaque save grant therefore reports readwrite even though getFile correctly rejects read access. Directory grants can similarly overclaim a combined permission from only a subset of read/enumerate/write/create/delete authority.
Focused scope
- Derive read and readwrite permission states from the exact opaque grant capability set; readwrite requires both readable and writable authority for the handle kind.
- Preserve browser dictionary/default/invalid-mode and illegal-receiver behavior.
- Treat AppScene grants as terminal granted/denied capability decisions. Do not invent a prompt/elevation operation, replay picker activation, or mutate native authority in JavaScript.
- Preserve permission state through transient structured clone and durable IndexedDB restore, including origin/profile retirement behavior.
- Add Chromium/spec oracle coverage, native real-V8 security/lifecycle coverage, capability adapter assertions, and bounded 100/10,000-cycle heap/RSS/FD/latency gates.
Boundaries
This child does not add create/delete/remove/move authority, raw paths, permission prompts, AppScene changes, CSS, History #392, resource #388, consolidation #76, or vscode-demo changes. Missing native entry mutation remains a separate authority dependency.
Refs #248
Parent: #248
Native authority: SceneTech/AppScene#123
Reproduction
At WebScene 2ffb0dc, FileSystemHandle.queryPermission({mode:"readwrite"}) and requestPermission({mode:"readwrite"}) return granted whenever any write-like grant bit is present. A write/create-only opaque save grant therefore reports readwrite even though getFile correctly rejects read access. Directory grants can similarly overclaim a combined permission from only a subset of read/enumerate/write/create/delete authority.
Focused scope
Boundaries
This child does not add create/delete/remove/move authority, raw paths, permission prompts, AppScene changes, CSS, History #392, resource #388, consolidation #76, or vscode-demo changes. Missing native entry mutation remains a separate authority dependency.
Refs #248