You seem to have the sources and destinations of your rules confused. You have allowed “Packets coming from source WIFI_AP net into interface LAN destined for LAN net”. But what you want is to allow “Packets coming from source LAN net into interface LAN destined for WIFI_AP net”.
That means, you need to swap source and destination on the rule in the LAN tab. If access from the PC on the LAN to the WIFI AP is the only thing you want, you won’t need any other rules.