For example, if they're all *.local that wouldn't be easily abusable.
All-in-all, this is something that could easily be made into an app and automated.
Secure versions of this exist - and the security requirements they introduce are part of the reason enterprise IT is so much of a pain in the ass.
Regardless, we are talking about users' browsers dropping plain HTTP. These browsers will never hit your backend servers, so you need not worry about them. In your scenario, they'll always use HTTPS. You are worried about your one in a million case as a developer. That's fine, go into about:config and enable plain HTTP. Everyone else isn't an expert in security and shouldn't be allowed to shoot themselves in the foot by default.
python3 -m http.server
and then opening http://[::1]:8000/ in your web browser.But then again, carrier-grade NAT means that anyone who is tinkering like this has to do some sort of NAT-punching to show their work off to a friend, so maybe this could be solved by an automated wrapper ala localtunnel or ngrok.
openssl s_server -accept 4443 -WWW -cert mycert.pem
Is not much more complicated.Thanks. I know about that, but I am not on a mac.