Didn't have time to finish this for 1.0. The security chapter should cover: - [ ] Require HTTPS for controllers (or the whole project) - [ ] Debugging HTTPS locally