Remove protect_from_forgery in ApiController, which is disabled by the following skip_before_action, as well.
* Keep ENV['LOCAL_HTTPS'] with ApplicationControllerSpec (fix random fail) * use climate_control
This change also adds a specification for the method.