The discussion about enforcing Secure Boot is kind of missing the point - if Secure Boot isn't enabled, earlier code could simply pass a fake pointer to the EFI runtime services table and fake GetVariable(), making it look like Secure Boot is enabled and appropriately configured. There's no real programmatic way to verify that Secure Boot is enabled[1], you pretty much just have to assert that it is.
[1] Well, kind of. The Secure Boot configuration state is measured into PCR 7 on the TPM, so you can seal a secret to it and then have it fail if the Secure Boot configuration changes. But that's made difficult because updates to dbx (but not dbt) invalidate the state, so you need a lot of very careful handshaking in blacklist updates.