You are quite correct, but by this stage the original definition of REST to include HATEOAS has pretty much been abandoned by most people.
Edit: Pretty much every REST API I see these days explains how to construct your URLs to do different things - rather than treating all URLs as opaque. Mind you having tried to create 'pure' HATEOAS REST API I think I prefer the contemporary approach!