Right now, unless it is ssl, you can't send a secure session cookie. It is perfectly valid to do this for localhost, and very desirable for development.
In lib/rack/session/abstract/id.rb, I think it should say something like:
def security_matches?(request,options)
return true unless options[:secure]
request.ssl? || request.host == "localhost"
end