Revisit flatpak permissions
The permissions used at flathub [1] and evince at some point forked, with the flathub requiring fewer and more strict permissions over time. These permissions leaked from upstream evince to papers when the project was forked and it might be a good idea to revisit whether the permissions here are optimal.
[1] https://github.com/flathub/org.gnome.Evince/blob/master/org.gnome.Evince.json