I think the most bulletproof solution is to save only the code inside your SSL document. This ensures that you (or another developer in the future) cannot accidentally associate yourself with an unprotected version of the form. If you have a form in both HTTP and HTTPS, you may not even notice that the incorrect one is used by accident.
, . URL- Apache , , - HTTP.