Against a defenseless country looking to surrender that couldn't retaliate. Will be a bit different if it initiates nuclear war against Russia or China.
You can store the user info in the JWT so you don't need to hit the database to get user info every time. I usually just store an id in each issued token and store/remove it from redis or memory as needed for invalidating it.