Earlier quoted context omitted.
localhost is a secure context. so.. presumably we're just waiting for .internal to be added to the white list.
No. The concept of a DMZ died decades ago. You could still be MITM within your company intranet. Any system designed these days should follow zero-trust principles.
That is very much not true. Most corporate networks I've ever been on trust the internal network. Whether or not you think they should, they do.