Returns the QR code of a guest as a PNG image, to show in emails and the app. When the visit is not authorized, or the guest has no valid COVID questionnaire or vaccine (when COVID checks apply) or is banned, a "pending" placeholder image is returned instead; an unknown visit returns a "not found" image.Public: no session token is required.