Do we need an easier toggle for `request.is_secure()` to be True?

@CodenameTim posted a similar point about the middleware over here:

You might want to also join the discussion there @vanschelven. (I think there’s a general vibe in support of something there, so it’s bandwidth to get it over the line…)