Critical-risk tools in Webcake Storefront
31 of the 287 tools in Webcake Storefront are classified as critical risk. This page profiles those tools specifically, with recommended policy actions and the attack patterns that target them.
Every operation listed below is an action PolicyLayer recommends controlling at the transport layer. Open any tool to see the full profile, risk score, and YAML policy snippet.
Tools at critical risk
-
clear_page_draftDestructiveDelete a local page draft (does NOT delete any backend page already created from it).
-
delete_affiliate_accountsDestructiveRemove affiliate accounts.
-
delete_affiliate_productsDestructiveRemove products from the affiliate program.
-
delete_appointment_addressesDestructiveDelete appointment locations by id.
-
delete_appointment_calendarsDestructiveDelete booking calendars by id.
-
delete_appointment_classifiesDestructiveDelete appointment classifies by id.
-
delete_appointment_employeesDestructiveDelete appointment employees by id.
-
delete_articleDestructiveDelete a blog article
-
delete_automationDestructiveDelete one or more automations by id.
-
delete_collectionDestructiveDelete a collection (table) and all its records by id. Irreversible.
-
delete_contactsDestructiveDelete contacts by id.
-
delete_courseDestructiveDelete a course by id (also deletes its tracks).
-
delete_coursesDestructiveDelete multiple courses by id.
-
delete_domainDestructiveDetach/delete a custom domain from the site.
-
delete_employeesDestructiveRemove employees (and any pending invitations) by site_permission id.
-
delete_global_sectionDestructiveDelete a global section (Header/Footer/block) and remove its node from every page source. Two-step safety: dry_run=true (default) shows which pages would change; dry_run=false p...
-
delete_global_sourceDestructiveDelete a global source and its published version
-
delete_pageDestructiveDelete a page
-
delete_partner_feedsDestructiveDelete product feeds by id.
-
delete_productDestructiveDelete one or more products by id.
-
delete_product_categoryDestructiveDelete one or more product categories by id.
-
delete_redirect_urlsDestructiveDelete redirect URLs by id.
-
delete_saved_filterDestructiveDelete (or dismiss, if not owner) a saved filter by id.
-
delete_site_utmsDestructiveDelete UTM links by id.
-
delete_subscribersDestructiveDelete subscribers by id.
-
empty_media_trashDestructivePermanently delete all trashed media folders and content.
-
remove_fontDestructiveRemove a font by id.
-
remove_font_groupDestructiveRemove a font group by id.
-
remove_reviewsDestructiveDelete one or more reviews by id.
-
unblock_all_phone_customersDestructiveRemove all blocked customer phone numbers for the site.
-
uninstall_appDestructiveUninstall (remove) an installed application from the current site. Pass the app
Attacks that target this class
Critical-risk tools in any server share these documented attack patterns. Each links to the full case and the defensive policy.