What would prevent the user from simply adding another key once they are logged in for the next time or disabling the script. '~/.ssh/authorized_keys' can be can be read and modified by the user which is currently logged in...
The idea behind this initially was to have 1 key available on say, a flash drive, as a last-resort option for remote logins. This way, even if the key is stolen, it can't be used.
That's what I also thought. But wouldn't it be possible to change the ownership of the authorized_keys file to root? Otherwise maybe am backup of the authorized_keys file and rollback after logout would be an option.