1-click relay services are an awesome idea.
What I would do:
Make it accept events by only one pub key by default. This limits liability. Only events written by the author can be uploaded to the relay via websockets. Anyone can download them. No other events get in.
Internally,...