How to handle non-resource POST request and response ? (like session login)

This topic seems to touch on it well.

On a better note I honestly think being more authorization scheme adherent would be the better policy, in which case you could provide a link to the login URL with the appropriate vocabulary.

Are you asking about any additional scenarios as well, or is this strictly limited to auth?