[BrowserAPI] Change "browser" permission to certified apps only


As discussed in mozlandia we both think it's a mistake to allow privileged app to use browser-api. We should change it to certified only, or restrict a subset to certified only.
We're using this API in our app:
I chatted a bit with Paul about that. While not ideal, he believes we are not at risk of permission leakage because of csp and origin checks. So hold on for now.
I think getScreenshot() is probably the most privileged bit of the Browser API?

