## ADDED Requirements ### Requirement: Merchant self-service shop profile A shop owner SHALL set their own shop's profile with `PUT /api/shop/profile`, which upserts the profile row of the shop the caller owns and returns the composed shop profile. The write SHALL require an authenticated user with a shop under the `own_shop` scope and SHALL accept logo and banner URLs, company, region, and bilingual `address`, `notice` and `after_sale` text with the same `{ en, zh }` validation as the platform-admin profile write. Profile scores remain platform-set: merchant-supplied `score_rating`, `score_agreement`, `score_service` or `score_speed` values SHALL NOT be stored. A user without a shop SHALL be refused, and the platform-admin write and public reads SHALL keep their existing behavior. #### Scenario: merchant upsert round-trips - **WHEN** a shop owner sets their profile and the storefront reads the shop by slug - **THEN** the public read returns those values for that shop #### Scenario: incomplete bilingual text is refused - **WHEN** a shop owner submits a notice with only `en` text - **THEN** the request is refused and the stored profile is unchanged #### Scenario: merchant cannot set scores - **WHEN** a shop owner submits score values with their profile - **THEN** the stored scores are unchanged #### Scenario: a user without a shop is refused - **WHEN** a signed-in customer sends the merchant profile write - **THEN** the API refuses the write