I think this is just a comment on Firejail's implementation, as I think Firejail runs as root and thus must enforce its own permission checks.
It seems like bubblewrap uses a mount namespace created by the current user which would allow controlling access without any special checks.