Minimum permissions for read-only OSDK access with an object security policy

I’m validating a browser OSDK/OAuth read-only test on Developer Tier.

The object type is saved in a project and has an object security policy requiring the current user’s ID in an authorized-principal array. The tester has Hosted Website Viewer. Resource-level grants are disabled.

What exact custom-role operations are required, granted only on this object type, for metadata retrieval, object lookup and filtered search—with no backing-dataset access, editing or resharing?

Is ontology:view-object-type sufficient? Can foundry-data-proxy:get-files and security-rid-manager:write-secured-resources be omitted?

Please also confirm the required OAuth read scope and how to verify whether separate download restrictions are enforced for my enrollment.

The test must allow metadata retrieval while excluding another user’s case from lookup and search.