Logging a user in in code is relatively simple. It's up to you to qualify the user, then just do something like this (assuming that the user in in the modx_users table):
$usr = $modx->getObject('modUser', $criterion);
$modx->user =& $usr;
$modx->getUser();
/* $contexts = $modx->getOption('sbsContexts', $sp, $modx->context->get('key'));
$contexts = explode(',', $contexts); */
$contexts=array('web');
/* no auto login to 'mgr' context */
if (isset($contexts['mgr'])) {
unset ($contexts['mgr']);
}
foreach ($contexts as $ctx) {
$ctx = trim($ctx);
if (!empty ($ctx)) {
$modx->user->addSessionContext($ctx);
}
}
$modx->sendRedirect($url);
You don't even need Login or a plugin. The code above could be in a snippet. The only issue is making it secure.
Storing information in the user profile is also very simple, though the user can see their information if they have access to the Manager. You can store it in an unused profile field or in the profile's 'extended' field, but a better option is probably these two fields of the user object:
remote_key (string)
remote_data (json)
In that case, you woudn't even need to get the User Profile.