In my experience, enforcing log-in for for this kind of consumer product done for the sake of security, rather than user hostility. Internet connected hardware on a home network is a very attractive attack vector, especially if commands are unauthenticated.
Yes, and the same goes for information about the WiFi network. Lots of apps for IoT devices require this information to set up products, but the OS presents this as location tracking.
Yes, although they won't get the whole Wi-Fi scan list, which means no fine grained triangulation, and also no BSSID, but it's definitely imperfect.
It's also very frustrating if you are using the Wi-Fi APIs for legitimate purposes. Having to explain to a user why you need location permissions in order to set up a Wi-Fi peripheral isn't easy.