In regards to sandboxing, it only gets as far in the way as you ask it to. For applications that you're not planning on putting on FlatHub anyway you can be just as open as you want to be, i.e. just adding /
- or host
as it's called - as read-write to the app. (OpenMW still does that as we had some issues with the data extraction for original Morrowind install media)
If you do want to sandbox though, users are able to poke just as many holes as they want - or add their own restrictions atop whatever sandboxing you set up for the application. Flatpak itself has the flatpak override
tool for this, or there's graphical UIs like flatseal and the KDE control center module..
Well, Flatpak always builds the aliases, so as long as the
<installation>/exports/bin
folder is in$PATH
there's no need to symlink.If you're talking specifically about having symlinks with some arbitrary name that you prefer, then that's something you'll have to do yourself, the Flatpak applications only provide their canonical name after all.
You could probably do something like that with inotify and a simple script though, just point it at the
exports/bin
folders for the installations that you care about, and set up your own mapping between canonical names and whatever names you prefer.