Thread `suggestedScope` through the app-server permission approval
request and use it when constructing TUI approval requests. This
keeps the protocol backward compatible by defaulting the field to
`turn` when older clients omit it.
Add focused app-server and TUI coverage, plus a snapshot for the
session-suggested approval overlay so reviewers can see the
preselected session row.