in your nginx config you do this for https setup: # needed for HTTPS proxy_set_header X-FORWARDED-PROTO https;
then if you want, you can check in rails that certain controllers received https requests.
using nginx as proxy means your rails app only ever deals with plain text http.
the only issue, with all http -> https transitions is making sure that things you are storing in sessions are placed in your forms if you go from a http page to an https page on form submission. If not you will lose state if you are storing sessions in the cookies.
The part about relative urls is right. Using cdns etc makes things harder if they don't support your ssl cert.
At CarWoo! once you login we do everything behind https. For our user creation form you can be on an http page, but it submits to https.
We created partials that represent our sign up forms (we have many kinds of landing pages) that automatically take important things out of the session and put them in the form if needed. These things are not security risks, but are important for the correct functionality of the app.