Well, keep in mind that the content server is capable of writing to both the library (via calibredb) and the userdb (there is a new option to edit your password directly from the browser). So you might not want to run it as root, if only because you can end up with root-owned files without meaning to.