Looks like it's very close to what I meant!
I was thinking of something like `/usr/bin/firefox --webapp-mode /var/opt/path/to/approot/` (in my model, the browser would contain code to load some standard webapp format, while with Tauri it looks like the app bundles a small piece of code that loads local webkit) but that's just a detail.
The downside of Tauri is that you likely run the built-in runtime with regular (full) access, while with a browser-controlled flow, the browser could enforce a permission system.