All the CGI scripts will run as the same user, so they have potential to conflict with other scripts.
Store in computer x--,---,--- It's owned by root, and reads in at startup before changing UIDs.
passwords and client-side certificates.Passwords should never be used without encrypting the network connection.Challenge: if all scripts run with the same permission, and if local users have read-access to user content, how can a user do safe upload?Use a password manager such as 1password!