It seems it’s not possible to avoid this, which is not optimal but ok for me.
I would like to know whether I can safely disable “allow OEM unlocking” in Android’s (i.e. iode’s) developer settings? Is that fine or is it possible to brick the phone?
Sorry if this is a stupid question, but I really don’t want to brick my phone (and I never flashed a ROM before).
It seems to me that if I keep that enabled, it’s basically useless to have a locked bootloader as you can just boot into fastboot and unlock the bootloader from there. So to get the better security I should disable that in iodeOS, right?
(If I disable the option now and it breaks, afaik I will not be able to unlock the bootloader again, i.e. it would be bricked then)
As that thread mentions, this is not possible to avoid. It is your “badge of honor” you are using a privacy respecting ROM
If your bootloader is now locked and booting correctly you should be able to disable “Allow OEM Unlocking”, but honestly you are right, if a future update ever causes an issue that won’t boot, you would then not be able to unlock the device to reflash it and may have a brick. I don’t personally see that keeping it allowed causes any risk for you: If the device is unlocked by a malicious person, then your data is all wiped out. If it is tampered with in any way without unlocking it, it will then refuse to boot as the chain of trust would be broken when it attempts to boot.
“TL;DR:” personally I would just leave it as you have it now But the decision is yours.