I’ve been using certificate based auth on https for ages on my ops stuff. Most devices support just slapping an SSL/TLS key into their os, but not everything.
But when I wanted to use it for Jellyfin, I found TVs and sticks aren’t all straightforward.
In your link, they closed that ticket as not planned because they intend to implement FIDO’s secure exchange protocols. https://github.com/keepassxreboot/keepassxc/issues/11363
It should (hopefully) be secure when they get done.
My demons are all Doctor Who. I had it mostly straight in plaques and when I moved over to jelly fin, nothing was right.