nope u missed big part last leg cleartxt - hence using any cert to encrypt is big think who issue cert is not important - dummy self sign whatever so long sniffer cannot be content is good enough
Only if you are visiting a normal website. For .onion site, it is e2e encrypted. Actually says it here too: https://tb-manual.torproject.org/onion-services/