always outputting empy array, although despite sql injection select * from sys_user where user_name = ${param}