Seems odd to me that they would encourage allowing 3rd party sites to read all your email, but I guess this is where we're at right now
I think the rationale is that the page has to be a real permissions page to give the attacker access to your data. A fake page won't have any power in that regard.
And on a real permissions page, an attacker won't be able to fake the requesting app's link.
So: legit page + legit link = no phishing ... even though it is by no means a safe situation.