In test setup blocks:
@request.env['HTTPS'] = 'on'
@request.env['SERVER_PORT'] = 443
You can stub out TLS/SSL. Then, ensure your require SSL definition in your controller returns a HTTP 426 status if it's not over SSL.Your tests expect a 200 response, not a 426 or 302. 302 is bad -- you've already submitted via plaintext once (I'm looking at you, ssl_requirement). Fail fast and fix your code.
SSL will be disabled for only localhost requests.
def ssl_enabled?
!(request.local?)
end
This has been tested on dozens of computers.