

By default this applications allows when adding a server, that the communication is not encrypted between the app and the server. This should be configured by default to enforce TLS encryption.
That’s not true. For public endpoints, HTTPS is enforced. You can’t use HTTP. For private IPs, yes HTTP is allowed. So “by default… not encrypted” is not correct and misleading.
Your original question didn’t mention servers specifically, so teawrecks’ interpretation wasn’t unreasonable. And ‘we’? It was just you and teawrecks in that thread.