my $tainted_username = param( 'username' ) || '';