Require any attribute that is going to be mass assigned to be whitelisted, and whitelist those attributes which need it
preferences table and moving tokens into a tokens table so that a user can have more than one.