Yep, it means that. If you are doing a full tunnel (I.e. the hub is the default route) then no traffic will exit the spoke directly to the internet, it will all go into the tunnel and exit via the hub. However, I’d suggest that more often than not the spoke MX would be configured as split tunnel so internet traffic gets routed directly from the spoke MX so the hub doesn’t become a bottleneck.
Configuring the firewall rules on a MX isn’t generally too hard anyway. By default they allow all outbound initiated connections, and deny all inbound initiated connections.