and let’s hope that the login page doesn’t have any vulnerabilities…
Home assistant also supports mTLS.
home assistant is something you'd likely ever want to allow from a handful of trusted devices, so deploying a client certificate on them can make sense.
This way a non-onboarded device doesn't even get to the html part, it's denied upstream by a reverse proxy before HA is involved.