And why should you need permission to do this?
Xiaomi historically had a problem with resellers installing malware in custom ROM on their phones, so they started putting up more and more obstacles to unlocking the bootloader over time, while still providing an avenue for legitimate customers to unlock.
I don't know what spurred the current action though.
This send like the relevant bit: