public AccountUser FindUser(string userName) { SqlConnection connect = new SqlConnection(@"Data Source=(localdb)\MSSQLLocalDB;Initial Catalog=UserAccounts;Integrated Security=True"); connect.Open(); SqlDataReader read = null; SqlCommand command = new SqlCommand("select * from Users where Us_name = '" + userName + "'", connect); read = command.ExecuteReader(); AccountUser user = new AccountUser(); if (read.Read()) { user.UserName = String.Format("{0}", read["Us_name"].ToString()); user.UserRoots = String.Format("{0}", read["Us_root"].ToString()); } else { user.UserName = "******"; } connect.Close(); return(user); }