- GET /api/events/all gains an opt-in excludeClosed=true param, used only by
the kiosk, so closed events no longer show as selectable there while other
admin/supervisor screens that still need to see closed events are unaffected.
- GET /api/users/check-exists now also returns the matched account's name,
email, phone, and notification preference (safe fields only). The kiosk's
existing debounced lookup uses this to autofill whichever fields are still
blank when a visitor enters an email or phone that matches an existing
account, without overwriting anything already typed.