True but there's still a way. Unless you've got HSTS enabled most users,
if they manually type in the URL, will leave out the protocol altogether which means the server needs to redirect you to https. That's no problem but there's always the chance that someone can perform an https stripping attack and catch the connection before the redirect occurs. Even with HSTS enabled the first time a user does this they're still vulnerable as HSTS cannot be activated until you have an initial https connection.
Chrome's HSTS list solves this but you have to make sure you send the Chromium team an email to add you to the list and even then not everyone uses Chrome. I had them add my app to the list recently which makes me feel warm and fuzzy but its not bullet proof.
In the end, yeah it's a real narrow edge case but as we all have been warned and seen so many times here on HN, those edge cases, no matter how narrow, often end up becoming real at some point. That's not to say I think it'll happen, just saying there is a way.