[deleted] I'm not sure the link you sent supports what you're claiming. It says that apps can use the Storage Access Framework which allows the the user to utilize a system picker to grant the app access to a specific document, regardless of whether it's inside or out of its storage scope. I didn't see anything about apps having default full access to all files within certain directories.
Let me know if I missed the specific section you're referring to that backs up your claim.