48dd9c87cf
Completes the typed cua_browser_* route (PR #74166 lineage) with the authorization surface that makes existing-profile attachment and repeatable bounded automation reachable by real users: - hermes computer-use browser-approve: CLI passthrough that mints cua-driver's five-minute single-use attachment token for one exact (pid, window_id). The user, never the model, is the token source. - approval_token passthrough on cua_browser_prepare (schema + dispatch + browser_route), forwarded only for existing_profile and only as a non-empty string. - computer_use.permission_mode: bounded + capability_manifest config: private per-session embedded daemon launched with --capability-manifest/--approve-capability-manifest; missing manifest fails loudly. 'unrestricted' is deliberately NOT a config value — it stays bound to the explicit per-session YOLO toggle. - Skill + system-prompt + docs guidance for the three authorization rungs and the isolated-profile-first default. E2E-verified against a temp HERMES_HOME: real config resolution to bounded, loud failure without a manifest, real argparse path driving a fake cua-driver binary, standard default preserved.