Reported issues for Django Admin MCP
Pod holds 24 of 32 GitHub reports that passed its relevance review. This can include external user reports, maintainer-confirmed bugs, and concrete feature gaps. Treat them as evidence to inspect, not a count of distinct defects.
Back to Django Admin MCP.
Most discussed
Unauthorized Error
I have an already-built Django Admin project. I have done all the mentioned steps, but I am getting an Unauthorized error.
Where could the problem be? What should I check?
Note: I am using the MCP Inspector -> npx @modelcontextprotocol/inspector
Thanks.
Error:
`Unauthorized: /mcp/ [17/Jul/2026 06:42:00] "POST /mcp/ HTTP/1.1" 401 52 [17/Jul/2026 06:42:00] "OPTIONS /.well-known/oauth-protected-resource/mcp HTTP/1.1" 200 0 [17/Jul/2026 06:42:01] "OPTIONS…
Read the thread · 2026-07-17 · closed · external user · 1 comment
Add MCP Resources support
Description
The MCP protocol supports Resources as a primitive for exposing data that agents can read. This package currently only implements Tools.
MCP Resources Overview
Resources provide read-only access to data, complementing the action-oriented Tools. They're ideal for:
- Browsing data without executing operations
- Providing context to agents
- Exposing configuration and metadata
Proposed Resources
Model Metadata Resources
models://- List of all exposed models…
Read the thread · 2026-01-24 · closed · 1 comment
Add MCP Prompts support
Description
The MCP protocol supports Prompts as a primitive for providing templated messages/instructions to AI agents. This package currently only implements Tools.
MCP Prompts Overview
Prompts are reusable templates that help agents understand how to interact with the system. They can include:
- Pre-defined instructions for common operations
- Contextual guidance based on model metadata
- Best practices for CRUD operations
Proposed Prompts
Discovery & Understanding
-…
Read the thread · 2026-01-24 · closed · 1 comment
Respect has_module_permission() to hide models from discovery
Description
Django admin's has_module_permission() method controls whether a user can see models in the admin index. This is currently not checked by the MCP, allowing users to discover and potentially access models they shouldn't see.
Current Behavior
The find_models tool returns all models with MCPAdminMixin regardless of the user's module-level permissions.
Expected Behavior
The find_models tool should:
- Check
has_module_permission()for each model's app - Only…
Read the thread · 2026-01-24 · closed · 1 comment
Support intermediate confirmation pages for admin actions
Description
Django admin actions can define intermediate confirmation pages that require user input before executing. These are currently not supported by the MCP.
Current Behavior
Admin actions are executed immediately with the provided IDs. Actions that require intermediate pages (confirmation dialogs, additional input) cannot be properly used.
Expected Behavior
Support a two-step workflow for actions that require confirmation:
- First call returns `requires_confirmation:…
Read the thread · 2026-01-24 · closed · 1 comment
Enforce min_num constraint for inline editing
Description
When updating a model with inlines via update_<model>, the min_num constraint defined on InlineModelAdmin is not enforced.
Current Behavior
The MCP allows having fewer inline objects than required by the min_num setting on the inline admin.
Expected Behavior
The min_num constraint should be validated when:
- Creating a parent object with inlines
- Updating inlines (especially when deleting)
If the minimum count is not met, return a validation error.
##…
Read the thread · 2026-01-24 · closed · 1 comment
Enforce max_num constraint for inline editing
Description
When updating a model with inlines via update_<model>, the max_num constraint defined on InlineModelAdmin is not enforced.
Current Behavior
The MCP allows adding unlimited inline objects regardless of the max_num setting on the inline admin.
Expected Behavior
The max_num constraint should be checked when adding inlines via the update_<model> tool. If the limit would be exceeded, return a validation error.
Django Admin Reference
class…
[Read the thread](https://github.com/7tg/django-admin-mcp/issues/61) · 2026-01-24 · closed · 1 comment
### Remove backward compatibility: tokens without user should not have full access
## Summary
Currently, MCP tokens that have no associated user, groups, or direct permissions are granted **full access** to all operations. This was implemented as a backward compatibility measure but represents a security concern.
## Current Behavior
From `django_admin_mcp/models.py`:
```python
def has_perm(self, perm):
# If no user, groups, or permissions are set, allow everything (backward compatibility)
if not self.user and not self.groups.exists() and not…
[Read the thread](https://github.com/7tg/django-admin-mcp/issues/24) · 2026-01-23 · closed · 1 comment
## Most recent
### list_* silently drops invalid filters and order_by instead of erroring
## Problem
`list_<model>` silently drops filter and ordering parameters it does not accept, returning a success-shaped, **unfiltered** result. For an MCP client (typically an LLM agent) this is worse than an error: the agent believes the result set is filtered/ordered and acts on wrong data.
`_build_filter_query` (handlers/crud.py) skips, without any signal to the caller:
- unknown field names — `{"filters": {"nonexistent": "x"}}` → full unfiltered list
- relation traversal — `{"filters":…
[Read the thread](https://github.com/7tg/django-admin-mcp/issues/111) · 2026-09-16 · closed · 0 comments
### Input-validation gaps: pk=0 rejected as missing, non-list bulk delete silently no-ops, history offset ignored
Small confirmed robustness gaps, grouped:
**1. Falsy primary keys are rejected as missing.** Every id-taking handler guards with `if not obj_id:`, so a legitimate `pk=0` (integer PKs starting at 0, or an explicit `0` value) is answered with `{"error": "id parameter is required"}` instead of a lookup:
get_author {"id": 0} -> {"error": "id parameter is required"}
Affects `handle_get`, `handle_update`, `handle_delete`, `handle_related`, `handle_history`, and the per-item check in…
[Read the thread](https://github.com/7tg/django-admin-mcp/issues/110) · 2026-09-15 · closed · 0 comments
### JSON-RPC notifications other than notifications/initialized receive error responses
## Problem
Follow-up to #97. `mcp_endpoint` special-cases only `notifications/initialized` (empty HTTP 202); every other notification falls into the catch-all:
```python
elif method == "notifications/initialized":
return HttpResponse(status=202)
...
else:
return _jsonrpc_error(body.id, METHOD_NOT_FOUND, f"Method not found: {method}")
JSON-RPC 2.0 requires that notifications (requests without an id) never receive a response — not even an error. MCP clients routinely send other…
Read the thread · 2026-09-15 · closed · 0 comments
Grouped admin fields tuples make serialization return empty objects
Problem
serialize_instance() passes the admin's fields straight to model_to_dict(instance, fields=...). Django admin allows grouped (tupled) entries in fields to place several fields on one line:
class AuthorAdmin(MCPAdminMixin, admin.ModelAdmin):
fields = [("name", "email")] # valid Django admin config
model_to_dict compares each field name against the list with in, so a tuple never matches, and every field is silently dropped (verified):
get_author…
[Read the thread](https://github.com/7tg/django-admin-mcp/issues/107) · 2026-09-15 · closed · 0 comments
### related_* mishandles null FK (stray 'value' branch) and empty reverse one-to-one (internal error)
## Problem
Two `related_*` edge cases fall through to wrong responses (both verified):
**1. Null forward FK/O2O hits the leftover "value" branch.** After #90 removed arbitrary-attribute access, the trailing `else` in `handle_related` should be unreachable — but a `null=True` FK returns `None` from `getattr`, which has neither `.all` nor `._meta`:
related_gadget {"id": 1, "relation": "author"} # gadget.author is NULL -> {"relation": "author", "type": "value", "value": "None"}
The…
[Read the thread](https://github.com/7tg/django-admin-mcp/issues/106) · 2026-09-15 · closed · 0 comments
### Inline create/update ignores the inline admin's fields, exclude, and readonly_fields
## Problem
`_update_inlines()` in `handlers/crud.py` builds the inline form with every field writable, honoring only a custom `form` class:
```python
inline_form_class = getattr(inline_class, "form", None)
if inline_form_class is None or inline_form_class is ModelForm:
inline_form_class = modelform_factory(inline_model, fields="__all__")
The inline admin's fields, exclude, and readonly_fields are ignored. With:
class ArticleInline(admin.TabularInline):
model =…
[Read the thread](https://github.com/7tg/django-admin-mcp/issues/105) · 2026-09-15 · closed · 0 comments
### bulk update writes unredacted sensitive values into LogEntry, unlike single update
## Problem
Single create/update log through `crud._serialize_data_for_log()`, which redacts values of sensitive-looking keys (`password`, `token`, `secret`, `api_key`, `auth`, `credential`) before writing the admin `LogEntry`. `handle_bulk_update` in `handlers/actions.py` serializes the raw data inline instead:
```python
serialized_data = data_adapter.dump_json(data, fallback=str).decode()
...
_log_action(..., change_message=f"Bulk updated via MCP: {serialized_data}")
Verified — same…
Read the thread · 2026-09-15 · closed · 0 comments
search_fields operator prefixes (^, =, @) break list search and autocomplete entirely
Problem
Django admin search_fields support the standard operator prefixes ^ (startswith), = (iexact), @ (fulltext), plus field__lookup forms. The MCP search paths blindly append __icontains:
# handlers/crud.py _build_search_query and handlers/relations.py handle_autocomplete
q |= Q(**{f"{field}__icontains": term})
With a Django-standard admin like:
class AuthorAdmin(MCPAdminMixin, admin.ModelAdmin):
search_fields = ["^name", "=email"]
both…
Read the thread · 2026-09-15 · closed · 0 comments
Tool descriptions and describe_* expose metadata of fields hidden by mcp_fields/mcp_exclude_fields
Problem
mcp_fields / mcp_exclude_fields filter serialized values, but the schema surfaces ignore them:
tools/registry._get_field_info()embeds all model fields in thelist_*/create_*/update_*tool descriptionshandlers/meta.handle_describe()(_get_field_metadata) returns metadata for all fields- the
models://{model}/schemaresource reuseshandle_describe
Verified: with MCPTokenAdmin.mcp_exclude_fields = ["token_key", "token_hash", "salt"], both the…
Read the thread · 2026-09-15 · closed · 0 comments
tools/list is not filtered by the token's permissions, unlike find_models and resources/list
Problem
tools/list returns tools for every mcp_expose = True model, regardless of the requesting token's permissions. get_tools() in tools/registry.py takes no request/user at all:
def get_tools() -> list[Tool]:
tools = [get_find_models_tool()]
for _model_name, model_admin in get_exposed_models():
...
This is inconsistent with the rest of the surface:
find_modelsfilters byhas_module_permission+ view permission (#64)resources/list…
Read the thread · 2026-09-15 · closed · 0 comments
Admin hooks calling message_user() crash all MCP writes (create_mcptoken can never succeed)
Problem
Since #74/#95, all MCP writes go through ModelAdmin.save_model() / delete_model(). But the synthetic request MCP handlers use (MCPRequest in handlers/base.py, and the bare HttpRequest built in views._request_for_token) has no messages storage. Any admin hook that calls self.message_user(request, ...) — an extremely common pattern in save_model overrides — raises django.contrib.messages.api.MessageFailure, which aborts the surrounding transaction.atomic() block…
Read the thread · 2026-09-15 · closed · 0 comments
JSON-RPC endpoint returns non-envelope error bodies and wrong status codes
Summary
The JSON-RPC endpoint (mcp_endpoint) returns success responses in proper JSON-RPC envelopes, but most error paths fall back to bare {"error": ...} bodies with non-200 HTTP status codes, which JSON-RPC/MCP clients can't parse as protocol errors.
Deviations (django_admin_mcp/views.py)
| Case | Current behavior | Spec expectation |
|---|---|---|
Unparseable/invalid JSON body (views.py:114-119) |
{"error": "Invalid JSON in request body"}, HTTP 400 |
error envelope, code… |
Read the thread · 2026-09-15 · closed · 0 comments
Negative/invalid limit and offset in related_/history_ escape as unhandled HTTP 500
Summary
limit/offset are validated in handle_list (crud.py:446-449) but not in handle_related and handle_history. A negative or non-integer value raises an uncaught exception that escapes the handler — neither handler has an outer try/except, and call_tool()/the HTTP views don't catch either — so the client gets a raw HTTP 500 instead of a JSON error.
Affected code
django_admin_mcp/handlers/relations.py:59-60, 92—handle_related: `queryset[offset : offset +…
Read the thread · 2026-09-15 · closed · 0 comments
get_ include_related crashes on any model with a forward ForeignKey
Summary
get_<model> with include_related: true raises AttributeError: 'ForeignKey' object has no attribute 'get_accessor_name' for any model that has a forward ForeignKey, and the whole request comes back as {"error": "An internal error occurred"}. Since most real models have at least one FK, the feature effectively only works on leaf/root models.
Affected code
django_admin_mcp/handlers/crud.py:550-563 — handle_get:
for field in model._meta.get_fields():…
[Read the thread](https://github.com/7tg/django-admin-mcp/issues/93) · 2026-09-15 · closed · 0 comments
### Inline updates/deletes are not scoped to the parent object
## Summary
Inline items passed to `update_<model>` are looked up **by primary key only** — the handler never verifies that the inline row actually belongs to the parent object being updated. Any row of the inline model can be updated or deleted through any parent.
## Affected code
`django_admin_mcp/handlers/crud.py` — `_update_inlines`:
- Line 310 (delete): `inline_model.objects.filter(pk=item_id).delete()`
- Line 326 (update): `inline_obj = inline_model.objects.get(pk=item_id)`
Neither…
[Read the thread](https://github.com/7tg/django-admin-mcp/issues/92) · 2026-09-15 · closed · 0 comments
### Related and inline data served without permission checks on the related model
## Summary
Related-object serialization only checks permissions on the **parent** model. A token with `view` permission on model A can read rows of related model B without any permission on B, through three paths:
1. `related_<A>` with a relation pointing at B (`handlers/relations.py:98,105` — serializes related objects, no check on B)
2. `get_<A>` with `include_related: true` (`handlers/crud.py:550-565`)
3. `get_<A>` with `include_inlines: true` (`handlers/crud.py:546-547` →…
[Read the thread](https://github.com/7tg/django-admin-mcp/issues/91) · 2026-09-15 · closed · 0 comments
The remaining reports are on [the project's issue tracker](https://github.com/7tg/django-admin-mcp/issues).