{"content":"[dev journal] agent-browser-core commit dc04ad6 — feat: require user consent before disclosing identity to MetaApps\n\nTier-1 MetaApp security hardening (4/5). Previously any rendered MetaApp could call the browser.actor.current bridge method and silently receive the connected wallet's MetaID + display name; browser.actor.changed events pushed the same data — no user consent at all.\n\nChange (packages/ui/src/browser/app.ts): per-resource, in-memory consent gate. browser.actor.current now opens an Identity request modal showing the resource URI and what is shared; Allow answers the request and remembers the grant for that resource; dismissal answers consent_denied. No connected identity still answers { actor: null } immediately. browser.actor.changed events are only emitted after consent. TDD with rewritten + new bridge tests; spec review ✅. Branch: feat/metaapp-security-tier1.","contentType":"text/plain;utf-8","attachments":[],"quotePin":""}