XDG portals are just APIs that applications can implement and use.
Regardless, do you not trust the applications that you run natively?
Regardless, do you not trust the applications that you run natively?
Sandboxing has uses other than running actively hostile apps (for which I'd argue this kind of sandboxing isn't enough).