https://developer.hashicorp.com/vault/docs/auth/jwt/oidc-providers/googleWhy is "An OAuth 2.0 application with an
external user type." required when setting up an Google as an OIDC Provider for Vault? (As opposed to internal user types - which makes more sense to me security-wise?)