The kiosk previously ran a debounced background lookup on every keystroke
in the visitor Email/Phone fields, silently autofilling matches. Replaced
with a dedicated "Look up existing account" field that only searches when
the operator presses Enter or clicks Search, and matches exactly against
either email or phone (never both from one query, to avoid digits in an
email being misread as an unrelated phone number). Also simplified the
"account already exists" banner wording.
- GET /api/events/all gains an opt-in excludeClosed=true param, used only by
the kiosk, so closed events no longer show as selectable there while other
admin/supervisor screens that still need to see closed events are unaffected.
- GET /api/users/check-exists now also returns the matched account's name,
email, phone, and notification preference (safe fields only). The kiosk's
existing debounced lookup uses this to autofill whichever fields are still
blank when a visitor enters an email or phone that matches an existing
account, without overwriting anything already typed.