if ($modx->user = $modx->getObject('modUser', array('username' => $_POST['username']))){
$modx->user->addSessionContext('web');
if ($modx->user->isAuthenticated('web')) {
$message = 'user is authenticated';
}else{
$message = 'user is not authenticated';
}
$response = array(
'status' => true,
'message' => $message,
'user' => $modx->user->get('username')
);
}else{
$response = array(
'status' => false,
'message' => 'User not found'
);
}
This question has been answered by BobRay. See the first response.
I feel like this should be obvious and I'm just too stupid to see it.
Something to try, rather than trying to start a new session on the remote site, is to store your own session variable. Then forward to the Login page with &service=login.
A plugin in the Login process (attached to OnManagerAuthentication) can check for the session variable, and if it's there, tell MODX to log the user in the normal way. See this series of blog articles: https://bobsguides.com/blog.html/2016/04/06/bypassing-the-modx-manager-login-i/.