Does this actually work? I mean, wouldn't the application just go ahead and use those privileges anyway, since it was built into the API? I think this just makes you aware of the privileges it intends to use, and doesn't actually affect what the application can and cannot do. I'd love it if somebody could prove me wrong, though. This would be swell if it worked. :P
Short answer: your OAuth token includes permission status so yes, this should work.