Here is a part of the code
try{
string query = "select * from user where username=\'" + user + "\' || userID=\'" + user