In the official documentation, it is stated that the OAuth app that needs to be created in the project hosting the GSuite project needs to allow external access.
Unless I am wrong, this will allow all users having a valid Gmail account to be able to log in to my vault instance (even with no permissions, assuming I set up my policies and group mappings correctly).
There is no justification provided for such a configuration. Why is that? Doesn’t this pose a security risk?